Description
A context.json endpoint of Apache Unomi is vulnerable to MVEL and OGNL expression injection. An attacker could exploit this vulnerability using a specially-crafted expression to execute arbitrary code on the system.
Remediation
Upgrade to the latest version of Apache Unomi (=> 1.5.2)
References
Related Vulnerabilities
JavaMelody XML External Entity (XXE) vulnerability
WordPress Plugin Dynamic Content for Elementor Remote Code Execution (1.9.5.6)
TYPO3 Improper Input Validation Vulnerability (CVE-2014-9509)
WordPress Plugin weForms-Easy Drag & Drop Contact Form Builder CSV Injection (1.6.3)
TYPO3 Improper Input Validation Vulnerability (CVE-2013-7079)