diff --git a/dast/vulnerabilities/ssti/oob/blade-oob.yaml b/dast/vulnerabilities/ssti/oob/blade-oob.yaml index c8819967e5f..7e8077744b5 100644 --- a/dast/vulnerabilities/ssti/oob/blade-oob.yaml +++ b/dast/vulnerabilities/ssti/oob/blade-oob.yaml @@ -3,7 +3,7 @@ id: blade-oob info: name: Laravel Blade 11.27.2 - Out of Band Template Injection author: 0xAwali,DhiyaneshDK - severity: unknown + severity: high reference: - https://laravel.com/docs/11.x/blade - https://medium.com/@0xAwali/template-engines-injection-101-4f2fe59e5756 diff --git a/dast/vulnerabilities/ssti/oob/bottle-oob.yaml b/dast/vulnerabilities/ssti/oob/bottle-oob.yaml index e787c5d1c47..5962e92b137 100644 --- a/dast/vulnerabilities/ssti/oob/bottle-oob.yaml +++ b/dast/vulnerabilities/ssti/oob/bottle-oob.yaml @@ -3,7 +3,7 @@ id: bottle-oob info: name: Bottle - Out of Band Template Injection author: 0xAwali,DhiyaneshDK - severity: unknown + severity: high reference: - https://bottlepy.org/docs/dev/ - https://medium.com/@0xAwali/template-engines-injection-101-4f2fe59e5756 diff --git a/dast/vulnerabilities/ssti/oob/chameleon-oob.yaml b/dast/vulnerabilities/ssti/oob/chameleon-oob.yaml index a5a1b97d981..301f81f74aa 100644 --- a/dast/vulnerabilities/ssti/oob/chameleon-oob.yaml +++ b/dast/vulnerabilities/ssti/oob/chameleon-oob.yaml @@ -3,7 +3,7 @@ id: chameleon-oob info: name: Chameleon - Out of Band Template Injection author: 0xAwali,DhiyaneshDK - severity: unknown + severity: high reference: - https://chameleon.readthedocs.io/en/latest/ - https://medium.com/@0xAwali/template-engines-injection-101-4f2fe59e5756 diff --git a/dast/vulnerabilities/ssti/oob/dotjs-oob.yaml b/dast/vulnerabilities/ssti/oob/dotjs-oob.yaml index f63c0a6f0fb..094c8c0faa7 100644 --- a/dast/vulnerabilities/ssti/oob/dotjs-oob.yaml +++ b/dast/vulnerabilities/ssti/oob/dotjs-oob.yaml @@ -3,7 +3,7 @@ id: dotjs-oob info: name: DotJS - Out of Band Template Injection author: 0xAwali,DhiyaneshDK - severity: unknown + severity: high reference: - https://github.com/olado/doT - https://medium.com/@0xAwali/template-engines-injection-101-4f2fe59e5756 diff --git a/dast/vulnerabilities/ssti/oob/ejs-underscore-oob.yaml b/dast/vulnerabilities/ssti/oob/ejs-underscore-oob.yaml index b8153b90851..13c63f875e3 100644 --- a/dast/vulnerabilities/ssti/oob/ejs-underscore-oob.yaml +++ b/dast/vulnerabilities/ssti/oob/ejs-underscore-oob.yaml @@ -3,7 +3,7 @@ id: ejs-underscore-oob info: name: Ejs AND Underscore - Out of Band Template Injection author: 0xAwali,DhiyaneshDK - severity: unknown + severity: high reference: - https://ejs.co/ - https://underscorejs.org/ diff --git a/dast/vulnerabilities/ssti/oob/erb-erubi-erubis-oob.yaml b/dast/vulnerabilities/ssti/oob/erb-erubi-erubis-oob.yaml index 873b7452102..7b1393cdad4 100644 --- a/dast/vulnerabilities/ssti/oob/erb-erubi-erubis-oob.yaml +++ b/dast/vulnerabilities/ssti/oob/erb-erubi-erubis-oob.yaml @@ -3,7 +3,7 @@ id: erb-erubi-erubis-oob info: name: Erb OR Erubi OR Erubis - Out of Band Template Injection author: 0xAwali,DhiyaneshDK - severity: unknown + severity: high reference: - https://rubygems.org/gems/erb - https://rubygems.org/gems/erubis diff --git a/dast/vulnerabilities/ssti/oob/freemarker-oob.yaml b/dast/vulnerabilities/ssti/oob/freemarker-oob.yaml index 0b64399b0bb..8681b0b8981 100644 --- a/dast/vulnerabilities/ssti/oob/freemarker-oob.yaml +++ b/dast/vulnerabilities/ssti/oob/freemarker-oob.yaml @@ -3,7 +3,7 @@ id: freemarker-oob info: name: Freemarker 2.3.33 - Out of Band Template Injection author: 0xAwali,DhiyaneshDK - severity: unknown + severity: high reference: - https://mvnrepository.com/artifact/org.freemarker/freemarker - https://medium.com/@0xAwali/template-engines-injection-101-4f2fe59e5756 diff --git a/dast/vulnerabilities/ssti/oob/groovy-oob.yaml b/dast/vulnerabilities/ssti/oob/groovy-oob.yaml index 802438c119a..9b6b8e4f4c3 100644 --- a/dast/vulnerabilities/ssti/oob/groovy-oob.yaml +++ b/dast/vulnerabilities/ssti/oob/groovy-oob.yaml @@ -3,7 +3,7 @@ id: groovy-oob info: name: Groovy - Out of Band Template Injection author: 0xAwali,DhiyaneshDK - severity: unknown + severity: high reference: - https://docs.groovy-lang.org/ - https://medium.com/@0xAwali/template-engines-injection-101-4f2fe59e5756 diff --git a/dast/vulnerabilities/ssti/oob/jinja2-oob.yaml b/dast/vulnerabilities/ssti/oob/jinja2-oob.yaml index 188ff8a5ab3..e1857bcdb8d 100644 --- a/dast/vulnerabilities/ssti/oob/jinja2-oob.yaml +++ b/dast/vulnerabilities/ssti/oob/jinja2-oob.yaml @@ -3,7 +3,7 @@ id: jinja2-oob info: name: Jinja2 - Out of Band Template Injection author: 0xAwali,DhiyaneshDK - severity: unknown + severity: high reference: - https://pypi.org/project/Jinja2/ - https://medium.com/@0xAwali/template-engines-injection-101-4f2fe59e5756 diff --git a/dast/vulnerabilities/ssti/oob/latte-oob.yaml b/dast/vulnerabilities/ssti/oob/latte-oob.yaml index a53bf3f63aa..69623e213f7 100644 --- a/dast/vulnerabilities/ssti/oob/latte-oob.yaml +++ b/dast/vulnerabilities/ssti/oob/latte-oob.yaml @@ -3,7 +3,7 @@ id: latte-oob info: name: Latte 3.0.20 - Out of Band Template Injection author: 0xAwali,DhiyaneshDK - severity: unknown + severity: high reference: - https://github.com/nette/latte - https://medium.com/@0xAwali/template-engines-injection-101-4f2fe59e5756 diff --git a/dast/vulnerabilities/ssti/oob/mako-oob.yaml b/dast/vulnerabilities/ssti/oob/mako-oob.yaml index bbdcb318e5c..7dc3207a65f 100644 --- a/dast/vulnerabilities/ssti/oob/mako-oob.yaml +++ b/dast/vulnerabilities/ssti/oob/mako-oob.yaml @@ -3,7 +3,7 @@ id: mako-oob info: name: Mako - Out of Band Template Injection author: 0xAwali,DhiyaneshDK - severity: unknown + severity: high reference: - https://www.makotemplates.org/ - https://medium.com/@0xAwali/template-engines-injection-101-4f2fe59e5756 diff --git a/dast/vulnerabilities/ssti/oob/pugjs-oob.yaml b/dast/vulnerabilities/ssti/oob/pugjs-oob.yaml index 5cc3f7f131a..637eed4d582 100644 --- a/dast/vulnerabilities/ssti/oob/pugjs-oob.yaml +++ b/dast/vulnerabilities/ssti/oob/pugjs-oob.yaml @@ -3,7 +3,7 @@ id: pugjs-oob info: name: Pug.js - Out of Band Template Injection author: 0xAwali,DhiyaneshDK - severity: unknown + severity: high reference: - https://pugjs.org/ - https://medium.com/@0xAwali/template-engines-injection-101-4f2fe59e5756 diff --git a/dast/vulnerabilities/ssti/oob/tornado-oob.yaml b/dast/vulnerabilities/ssti/oob/tornado-oob.yaml index cce346af098..9a93948c3e2 100644 --- a/dast/vulnerabilities/ssti/oob/tornado-oob.yaml +++ b/dast/vulnerabilities/ssti/oob/tornado-oob.yaml @@ -3,7 +3,7 @@ id: tornado-oob info: name: Tornado - Out of Band Template Injection author: 0xAwali,DhiyaneshDK - severity: unknown + severity: high reference: - https://www.tornadoweb.org/en/stable/guide/templates.html - https://medium.com/@0xAwali/template-engines-injection-101-4f2fe59e5756 diff --git a/dast/vulnerabilities/ssti/oob/velocityjs-oob.yaml b/dast/vulnerabilities/ssti/oob/velocityjs-oob.yaml index 52eae74d526..ae41d530a81 100644 --- a/dast/vulnerabilities/ssti/oob/velocityjs-oob.yaml +++ b/dast/vulnerabilities/ssti/oob/velocityjs-oob.yaml @@ -3,7 +3,7 @@ id: velocityjs-oob info: name: VelocityJS 2.0.6 - Out of Band Template Injection author: 0xAwali,DhiyaneshDK - severity: unknown + severity: high reference: - https://www.npmjs.com/package/velocityjs - https://medium.com/@0xAwali/template-engines-injection-101-4f2fe59e5756