openEQUELLA 2026.1.0 之前的版本存在一个远程代码执行漏洞,原因是 FreeMarker 模板编译过程中使用了未经沙箱隔离的 配置。经过身份验证的攻击者可以通过在集合摘要、仪表板小部件或 MIME 模板中注入恶意的模板表达式,实例化诸如 等危险类,并调用 来执行任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| openequella | openEQUELLA | 0 ~ 2026.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet