Nuxeo prior to version 10.3 is susceptible to an unauthenticated remote code execution vulnerability via server-side template injection.
View the template here CVE-2018-16341.yaml
Lab | Machine | Link |
---|---|---|
Hack The Box | Hancliffe | Go to Practice |
References:
https://nvd.nist.gov/vuln/detail/CVE-2018-16341