VulnerabilityModified
CVE-2020-12827
MJML prior to 4.6.3 contains a path traversal vulnerability when processing the mj-include directive within an MJML document.
HIGH 7.2EPSS 2.66%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
MJML prior to 4.6.3 contains a path traversal vulnerability when processing the mj-include directive within an MJML document.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L
- EPSS
- 2.66% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- mjml/mjml
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/158111/MJML-4.6.2-Path-Traversal.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2020/Jun/23Exploit, Mailing List, Third Party Advisory
- https://github.com/mjmlio/mjml/commit/30e29ed2cdaec8684d60a6d12ea07b611c765a12Patch, Third Party Advisory
- https://github.com/mjmlio/mjml/releases/tag/v4.6.3Release Notes, Third Party Advisory
- https://mjml.io/communityVendor Advisory
- https://rcesecurity.comBroken Link
- https://twitter.com/mjmlioThird Party Advisory
- http://packetstormsecurity.com/files/158111/MJML-4.6.2-Path-Traversal.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2020/Jun/23Exploit, Mailing List, Third Party Advisory
- https://github.com/mjmlio/mjml/commit/30e29ed2cdaec8684d60a6d12ea07b611c765a12Patch, Third Party Advisory
- https://github.com/mjmlio/mjml/releases/tag/v4.6.3Release Notes, Third Party Advisory
- https://mjml.io/communityVendor Advisory
- https://rcesecurity.comBroken Link
- https://twitter.com/mjmlioThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.