Vulnerabilities/

ejs template injection vulnerability

Severity:
High

Description

The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view options][outputFunctionName]. This is parsed as an internal option, and overwrites the outputFunctionName option with an arbitrary OS command (which is executed upon template compilation).

Recommendation

Update the ejs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
ejs
Anything's wrong? Let us know Last updated on January 30, 2023

This issue is available in SmartScanner Professional

See Pricing