FusionAuth 1.10 Remote Command Execution
Posted by deepcore on January 29, 2020 – 3:08 am
FusionAuth versions 1.10 and below suffer from a remote command execution vulnerability. An authenticated attacker with enough privileges to access the template editing functions (either site templates or e-mail templates) in the FusionAuth dashboard can execute commands on the underlying operating system using the Apache FreeMarker Expression language.
Post a reply
You must be logged in to post a comment.