JsLink in Webswing before 2.6.12 LTS, and 2.7.x and 20.x before 20.1, allows remote code execution.
Link | Tags |
---|---|
https://bitbucket.org/meszarv/webswing/issues/375/webswing-jslink-mechanism-remote-code | issue tracking third party advisory |
https://www.webswing.org/docs/2.6/discover/release_notes.html#release-notes-2-6-12 | release notes vendor advisory |