Vulnerabilities > Craftercms > Studio > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-10-06 CVE-2020-25803 Improper Control of Dynamically-Managed Code Resources vulnerability in Craftercms Studio
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker template exposed objects.
network
low complexity
craftercms CWE-913
critical
9.0
2020-10-06 CVE-2020-25802 Improper Control of Dynamically-Managed Code Resources vulnerability in Craftercms Studio
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy scripting.
network
low complexity
craftercms CWE-913
critical
9.0