Impact
A Server‑Side Template Injection vulnerability in WGDashboard allows an authenticated attacker to inject malicious template expressions that are interpreted by the server. This flaw effectively lets the attacker execute arbitrary code with the highest available privileges, elevating the threat to full system compromise. The weakness corresponds to improper control of code generation through dynamic language features, identified as CWE-94 and CWE-1336.
Affected Systems
The affected product is WGDashboard version 4.3.2 and all earlier releases. No additional vendor or product variations are listed. Users running these versions must check the version number to determine susceptibility.
Risk and Exploitability
The vulnerability offers authenticated users a direct path to execute arbitrary commands as root, posing a severe impact. The EPSS score of < 1% indicates a very low likelihood of exploitation, while the CVSS score of 9.8 reflects catastrophic severity. The absence of a KEV listing suggests no confirmed widespread exploitation at this time. The lack of a public patch or workaround in the provided CNA data means organizations must act promptly once a fix becomes available. Existing exploitation would require the attacker to gain authenticated access first; thus, strong access controls and privilege separation are critical mitigants.
OpenCVE Enrichment