An issue in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to the Page Sandbox feature.
References
| Link | Resource |
|---|---|
| https://book.hacktricks.xyz/v/jp/pentesting-web/ssti-server-side-template-injection | Permissions Required |
| https://cxsecurity.com/issue/WLB-2024040049 | Exploit Third Party Advisory |
| https://book.hacktricks.xyz/v/jp/pentesting-web/ssti-server-side-template-injection | Permissions Required |
| https://cxsecurity.com/issue/WLB-2024040049 | Exploit Third Party Advisory |
Configurations
History
13 Jun 2025, 16:11
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Inducer
Inducer relate |
|
| CPE | cpe:2.3:a:inducer:relate:*:*:*:*:*:*:*:* | |
| References | () https://book.hacktricks.xyz/v/jp/pentesting-web/ssti-server-side-template-injection - Permissions Required | |
| References | () https://cxsecurity.com/issue/WLB-2024040049 - Exploit, Third Party Advisory |
21 Nov 2024, 09:14
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://book.hacktricks.xyz/v/jp/pentesting-web/ssti-server-side-template-injection - | |
| References | () https://cxsecurity.com/issue/WLB-2024040049 - |
25 Oct 2024, 20:35
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-918 |
03 Jul 2024, 01:56
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| CWE | CWE-1336 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
22 Apr 2024, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-04-22 19:15
Updated : 2025-06-13 16:11
NVD link : CVE-2024-32407
Mitre link : CVE-2024-32407
CVE.ORG link : CVE-2024-32407
JSON object : View
Products Affected
inducer
- relate
CWE
CWE-918
Server-Side Request Forgery (SSRF)
