Description
nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function
Remediation
References
http://www.securityfocus.com/bid/101897
https://snyk.io/vuln/npm:ejs:20161128
Related Vulnerabilities
CVE-2019-8331 Vulnerability in maven package org.webjars:bootstrap
CVE-2019-12395 Vulnerability in maven package us.dynmap:dynmap
CVE-2022-31147 Vulnerability in npm package jquery-validation
CVE-2022-47105 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base-core
CVE-2022-36093 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates