Impact
A security flaw exists in the ViewEngine component of the Furion .NET Framework, specifically within the RunCompile method of ViewEngine.cs. The flaw permits an attacker to inject specially crafted content that is not properly neutralized by the template engine’s parsing, potentially allowing unintended evaluation of template expressions. The flaw is triggered by manipulating the argument content passed to RunCompile; the resulting improper neutralization of template elements may lead to unintended code execution or other undesirable behavior. The attack can be executed remotely and the exploit has been released publicly.
Affected Systems
The vulnerability affects versions of the Furion .NET Framework up to 4.9.9.95. Organizations should identify installations of this framework running those versions and determine whether they incorporate the View Engine component described above.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk, yet the exploit is publicly available and can be triggered remotely. The EPSS score is not yet available, and the vulnerability is not listed in the CISA KEV catalog. The remote nature of the attack and the availability of an exploit raise the risk. The attack vector is likely to involve sending malicious template content to endpoints that invoke RunCompile; the precise exploitation conditions are only inferred from the description.
OpenCVE Enrichment