Server-Side Template Injection Vulnerability in Wirtualna Uczelnia
CVE-2026-34906

9.3CRITICAL

Key Information:

Vendor

Simple Sa

Vendor
CVE Published:
2 June 2026

What is CVE-2026-34906?

A security flaw in Wirtualna Uczelnia permits unauthenticated attackers to exploit Server-Side Template Injection, enabling Remote Code Execution. Insufficient validation of inputs in parameters like redirectToUrl and redirectUrlParameter allows the injection of arbitrary template expressions. This vulnerability could permit attackers to execute remote commands on the server, including the introduction of reverse shells, posing significant risks to the integrity and confidentiality of the system.

Affected Version(s)

Wirtualna Uczelnia 0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dawid Bakaj - VIPentest
.