Template Injection Vulnerability in Logpoint Could Lead to Code Execution
CVE-2022-48684
8.8HIGH
What is CVE-2022-48684?
A template injection issue was identified in Logpoint products prior to version 7.1.1. This vulnerability arises within the search template functionality, which utilizes jinja templating to dynamically generate data. Malicious actors can exploit this flaw if they have the ability to create a search template, enabling them to execute arbitrary code under the privileges of the loginspect user. This presents a significant risk, as it allows unauthorized actions within the system.