Files
CVEs-PoC/2018/CVE-2018-13818.md
T
2024-06-18 02:51:15 +02:00

751 B

CVE-2018-13818

Description

** DISPUTED ** Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search search_key parameter. NOTE: the vendor points out that Twig itself is not a web application and states that it is the responsibility of web applications using Twig to properly wrap input to it.

POC

Reference

Github

No PoCs found on GitHub currently.