Executive brief
Rejetto HTTP File Server (HFS) contains a template injection vulnerability due to improper neutralization of special elements. A remote, unauthenticated attacker can execute arbitrary commands on the host system by sending a specially crafted HTTP request.
Affected products
- Rejetto HTTP File Server (HFS) Up to and including 2.3m
Timeline
- 2024-07-09: disclosed
- 2024-07-09: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-07-09: advisory