2 results (0.007 seconds)

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

European Chemicals Agency IUCLID before 6.27.6 allows remote authenticated users to execute arbitrary code via Server Side Template Injection (SSTI) with a crafted template file. The attacker must have template manager permission. • https://iuclid6.echa.europa.eu https://iuclid6.echa.europa.eu/documents/1387205/1809530/note_v6.27.6.pdf/76545a65-e6be-6486-280a-7d7c3d2ad455?t=1677577170669 https://iuclid6.echa.europa.eu/download •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affected versions are 5.15.0 through 6.27.5. • https://iuclid6.echa.europa.eu https://iuclid6.echa.europa.eu/documents/1387205/1809530/note_v6.27.6.pdf/76545a65-e6be-6486-280a-7d7c3d2ad455?t=1677577170669 https://iuclid6.echa.europa.eu/download • CWE-798: Use of Hard-coded Credentials •