CVE ID(s)
I've only tested this on a sample project but from this simple code search I suspect there are vulnerable projects out there. I'd helpful to see if I can make more robust the query after the initial findings.
Report
Server Side Template Injection in ASP.NET MVC RazorEngine leads to Remote Code Execution vulnerabilities.
More info: Server Side Template Injection (SSTI) in ASP.NET Razor
PR: #4313
Yes, this is part of a two post series about ASP.NET MVC vulnerabilities and taint tracking with CodeQL.
Result(s)
CVE ID(s)
I've only tested this on a sample project but from this simple code search I suspect there are vulnerable projects out there. I'd helpful to see if I can make more robust the query after the initial findings.
Report
Server Side Template Injection in ASP.NET MVC RazorEngine leads to Remote Code Execution vulnerabilities.
More info: Server Side Template Injection (SSTI) in ASP.NET Razor
PR: #4313
Yes, this is part of a two post series about ASP.NET MVC vulnerabilities and taint tracking with CodeQL.
Result(s)