2 results (0.007 seconds)

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

02 May 2023 — European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affected versions are 5.15.0 through 6.27.5. • https://iuclid6.echa.europa.eu • CWE-798: Use of Hard-coded Credentials •

CVSS: 9.0EPSS: 0%CPEs: 1EXPL: 0

02 May 2023 — European Chemicals Agency IUCLID before 6.27.6 allows remote authenticated users to execute arbitrary code via Server Side Template Injection (SSTI) with a crafted template file. The attacker must have template manager permission. • https://iuclid6.echa.europa.eu • CWE-94: Improper Control of Generation of Code ('Code Injection') •