ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-28246”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-28246
Published
2022-05-31
CVSS:
9.8
ShadowTrackr CVSS:
8.2
Summary:
A Server-Side Template Injection (SSTI) was discovered in Form.io 2.0.0. This leads to Remote Code Execution during deletion of the default Email template URL. NOTE: the email templating service was removed after 2020. Additionally, the vendor disputes this issue indicating this is sandboxed and only executable by admins.