CVE-2020-8141 describes a critical server-side template injection vulnerability in the dot package v1.1.2, affecting the dot_project. This flaw allows an authenticated attacker to execute arbitrary code by manipulating template inputs or Object.prototype values, leading to high impact on confidentiality, integrity, and availability. Rated 8.8 HIGH on CVSS, this vulnerability is easily exploitable over the network with low attack complexity. While no public exploits, Metasploit modules, or community discussions are currently identified, its high severity warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1.2CPE matchmatch criteria | cpe:2.3:a:dot_project:dot:1.1.2:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.