Impact
The vulnerability lies in the GroovyClassLoader.parseClass method within the Message Template Handler of Dromara lamp-cloud. An attacker can supply crafted content in the DefMsgTemplate.content field that fails to neutralize special elements used by the template engine, enabling remote code execution. This weakness is identified as CWE-1336 (Improper Neutralization of Special Elements used in a Template Engine) and CWE-791 (Uncontrolled Memory Allocation). The impact is the potential for arbitrary code execution on the host, compromising confidentiality, integrity, and availability.
Affected Systems
Dromara lamp-cloud versions up to 5.6.2 are affected. The vulnerability is present in all deployments of lamp-cloud that include the Message Template Handler component. Specific vendor/products: Dromara lamp-cloud.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, so the exact likelihood of exploitation cannot be quantified from the current data. The vulnerability is not listed in CISA KEV, which suggests it has not yet been documented as a known exploited vulnerability. The attack vector described in the public disclosure states that the exploit can be launched remotely, likely by providing malicious template content over a network connection to the lamp-cloud application.
OpenCVE Enrichment