A Server-Side Template Injection issue was discovered in Crafter CMS 3.0.18. Attackers with developer privileges may execute OS commands by Creating/Editing a template file (.ftl filetype) that triggers a call to freemarker.template.utility.Execute in the FreeMarker library during rendering of a web page.
{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "3.0.18"
}
],
"source": "CPE_RANGE",
"cpe": "cpe:2.3:a:craftercms:crafter_cms:*:*:*:*:*:*:*:*"
}