Vulnerabilities > CVE-2023-26546 - Unspecified vulnerability in Echa.Europa Iuclid

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
echa-europa

Summary

European Chemicals Agency IUCLID before 6.27.6 allows remote authenticated users to execute arbitrary code via Server Side Template Injection (SSTI) with a crafted template file. The attacker must have template manager permission.

Vulnerable Configurations

Part Description Count
Application
Echa.Europa
1