{"id":"GHSA-4rmr-c2jx-vx27","summary":"Mustache remote code injection vulnerability","details":"In Mustache.php v2.0.0 through v2.14.0, Sections tag can lead to arbitrary php code execution even if strict_callables is true when section value is controllable.\n\n","aliases":["CVE-2022-0323"],"modified":"2024-02-16T07:59:53.974944Z","published":"2022-01-27T14:51:00Z","database_specific":{"github_reviewed_at":"2022-01-24T23:01:39Z","nvd_published_at":"2022-01-21T18:15:00Z","cwe_ids":["CWE-1336","CWE-94"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-0323"},{"type":"WEB","url":"https://github.com/bobthecow/mustache.php/commit/579ffa5c96e1d292c060b3dd62811ff01ad8c24e"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/mustache/mustache/CVE-2022-0323.yaml"},{"type":"PACKAGE","url":"https://github.com/bobthecow/mustache.php"},{"type":"WEB","url":"https://github.com/bobthecow/mustache.php/releases/tag/v2.14.1"},{"type":"WEB","url":"https://huntr.dev/bounties/a5f5a988-aa52-4443-839d-299a63f44fb7"}],"affected":[{"package":{"name":"mustache/mustache","ecosystem":"Packagist","purl":"pkg:composer/mustache/mustache"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.14.1"}]}],"versions":["v2.0.0","v2.0.1","v2.0.2","v2.1.0","v2.10.0","v2.11.0","v2.11.1","v2.12.0","v2.13.0","v2.14.0","v2.2.0","v2.3.0","v2.3.1","v2.4.0","v2.4.1","v2.5.0","v2.5.1","v2.6.0","v2.6.1","v2.7.0","v2.8.0","v2.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-4rmr-c2jx-vx27/GHSA-4rmr-c2jx-vx27.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}