Skip to content

Server Side Template Injection lead to RCE ASP.NET RazorEngine #182

Description

@cldrn

CVE ID(s)

I've only tested this on a sample project but from this simple code search I suspect there are vulnerable projects out there. I'd helpful to see if I can make more robust the query after the initial findings.

Report

Server Side Template Injection in ASP.NET MVC RazorEngine leads to Remote Code Execution vulnerabilities.

More info: Server Side Template Injection (SSTI) in ASP.NET Razor

PR: #4313

  • Are you planning to discuss this vulnerability submission publicly? (Blog Post, social networks, etc).

Yes, this is part of a two post series about ASP.NET MVC vulnerabilities and taint tracking with CodeQL.

Result(s)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    All For OneSubmissions to the All for One, One for All bounty

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions