An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via the name and description parameter of the Add/Update Project function
References
Configurations
No configuration.
History
15 Jul 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| CWE | CWE-94 | |
| References | () https://eslam3kl.gitbook.io/blog/web-application-findings/cve-2026-38450-aetopia-dam-server-side-template-injection - |
14 Jul 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-14 22:16
Updated : 2026-07-15 20:58
NVD link : CVE-2026-38450
Mitre link : CVE-2026-38450
CVE.ORG link : CVE-2026-38450
JSON object : View
Products Affected
No product.
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
