Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-29827 PoC — ejs 注入漏洞

Source
Associated Vulnerability
Title:ejs 注入漏洞 (CVE-2023-29827)
Description:Github ejs是嵌入式 JavaScript 模板。 ejs v3.1.9版本存在注入漏洞,该漏洞源于容易受到服务器端模板注入(SSTI)的攻击,攻击者利用该漏洞可以通过closeDelimiter参数的配置设置来实现模板注入。
Description
ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the configuration settings of the closeDelimiter parameter.
File Snapshot

id: CVE-2023-29827 info: name: Embedded JavaScript(EJS) 3.1.6 - Template Injection author: riti ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.