PT-2026-45879 · Alf.Io · Alf.Io
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
alf.io versions prior to 2.0-M5-2606
Description
A sandbox escape issue exists in the extension script engine of alf.io, an open source ticket reservation system. An authenticated administrator can execute arbitrary operating system commands on the server. The system uses a sandboxed Rhino environment to execute restricted JavaScript; however, the use of an unguarded injected Java object
returnClass combined with an incomplete AST (Abstract Syntax Tree) blocklist allows the sandbox to be bypassed via Java reflection. This flaw can be triggered through the Extensions API.Recommendations
Update alf.io to version 2.0-M5-2606.
Exploit
Fix
RCE
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alf.Io