CVE-2021-46703
06.03.2022, 06:15
In the IsolatedRazorEngine component of Antaris RazorEngine through 4.5.1-alpha001, an attacker can execute arbitrary .NET code in a sandboxed environment (if users can externally control template contents). NOTE: This vulnerability only affects products that are no longer supported by the maintainerEnginsight
Vendor | Product | Version |
---|---|---|
razorengine_project | razorengine | 𝑥 < 4.5.1 |
razorengine_project | razorengine | 4.5.1:alpha001 |
𝑥
= Vulnerable software versions