CRITICAL 9.8 NuGet
Code injection in RazorEngine
GHSA-ph3v-2hq5-5qfq · CVE-2021-46703
Published · Modified
Description
In the IsolatedRazorEngine component of Antaris RazorEngine through 4.5.1-alpha001, an attacker can execute arbitrary .NET code in a sandboxed environment (if users can externally control template contents). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes