{"id":"CVE-2018-9327","details":"Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to execute arbitrary code on the server. The instance has to be configured to use a document database (DirtyDB, CouchDB, MongoDB, or RethinkDB).","modified":"2026-04-10T04:09:02.460970Z","published":"2018-04-07T21:29:00.350Z","references":[{"type":"ADVISORY","url":"http://blog.etherpad.org/2018/04/07/important-release-1-6-4/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ether/etherpad-lite","events":[{"introduced":"e2ea82f8df23f7ba68b5873024ddef178748c8c9"},{"last_affected":"83597562c1dd8f9d284cc68a8a94b63cdac039a1"},{"introduced":"dcfb28799035f918a937243106f64dedeaef4b32"},{"fixed":"fa83de778cdc6e7c3b83e356b45b76b955ec63ba"}],"database_specific":{"versions":[{"introduced":"1.5.0"},{"last_affected":"1.5.7"},{"introduced":"1.6.0"},{"fixed":"1.6.4"}]}}],"versions":["1.6.0","1.6.1","1.6.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-9327.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}