Server-Side Template Injection Vulnerability in Wirtualna Uczelnia
CVE-2026-34906
9.3CRITICAL
What is CVE-2026-34906?
A security flaw in Wirtualna Uczelnia permits unauthenticated attackers to exploit Server-Side Template Injection, enabling Remote Code Execution. Insufficient validation of inputs in parameters like redirectToUrl and redirectUrlParameter allows the injection of arbitrary template expressions. This vulnerability could permit attackers to execute remote commands on the server, including the introduction of reverse shells, posing significant risks to the integrity and confidentiality of the system.
Affected Version(s)
Wirtualna Uczelnia 0
