Impact
Improper neutralization of special elements used in the template engine enables an attacker to inject server‑side code that is executed when the template is rendered, potentially compromising confidentiality, integrity, and availability of the web application. This vulnerability is a classic case of server‑side template injection, classified as CWE‑1336.
Affected Systems
Arma Digital Media Inc. Website Template versions up to 11092026 are affected. No newer releases have been confirmed to contain a fix and the vendor has not responded to the disclosure.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score of < 1% suggests a very low likelihood of exploitation in practice, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a crafted HTTP request that includes malicious template syntax, which the engine interprets and executes.
OpenCVE Enrichment