PT-2026-67745 · Unknown · Lamp Rapid Development Platform
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LAMP Rapid Development Platform versions prior to 5.6.2 commit 84b0c27
Description
An issue exists in GlueFactory that allows the execution of unsandboxed Groovy scripts from database template fields without compilation restrictions or whitelisting. Attackers can manipulate the script field through message template endpoints to execute arbitrary Groovy code and operating system commands on the backend server.
Recommendations
Update LAMP Rapid Development Platform to the version containing commit 84b0c27.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lamp Rapid Development Platform