CVE Vulnerabilities

CVE-2024-37621

Improper Neutralization of Server-Side Includes (SSI) Within a Web Page

Published: Jun 17, 2024 | Modified: Jun 20, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io minimus.io echohq.com

StrongShop v1.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the component /shippingOptionConfig/index.blade.php.

Weakness

The product generates a web page, but does not neutralize or incorrectly neutralizes user-controllable input that could be interpreted as a server-side include (SSI) directive.

Affected Software

Name Vendor Start Version End Version
Strongshop Strongshop 1.0 (including) 1.0 (including)

References