CVE-2022-21648 describes a sandbox escape vulnerability in Latte, an open-source PHP template engine, affecting versions 2.8.0 through 2.8.7, 2.9.0 through 2.9.5, and 2.10.0 through 2.10.7. This flaw allows for injection into web pages generated from Latte templates, potentially leading to Cross-Site Scripting (XSS) attacks. The vulnerability is rated Medium severity (CVSS 6.1) with a low attack complexity and no authentication required, but user interaction is necessary for exploitation. While the impact on confidentiality and integrity is low, successful exploitation could compromise user sessions or deface websites. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) or community discussion has been observed. Patches are available in versions 2.8.8, 2.9.6, and 2.10.8, and users unable to upgrade should avoid accepting untrusted template input.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.8.0, < 2.8.8CPE matchmatch criteria | cpe:2.3:a:nette:latte:*:*:*:*:*:*:*:* | ||
>= 2.9.0, < 2.9.6CPE matchmatch criteria | cpe:2.3:a:nette:latte:*:*:*:*:*:*:*:* | ||
>= 2.10.0, < 2.10.8CPE matchmatch criteria | cpe:2.3:a:nette:latte:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.