CVE-2024-50658
Critical · CVSS 9.8AdPortal — Server-Side Template Injection (SSTI) RCE
- CVSS
- 9.8
- nvd
- EPSS
- 0.82%
- 53th pct
- KEV
- No
- Class
- other
- CWE-94
Description
Server-Side Template Injection (SSTI) was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code via the shippingAsBilling and firstname parameters in updateuserinfo.html file
Search profile — drives PoC discovery
Symbols shippingAsBillingfirstnameupdateuserinfo.html
Keywords CVE-2024-50658AdPortal SSTIAdPortal 3.0.39iPublishMedia AdPortalupdateuserinfo.html SSTIshippingAsBilling SSTIAdPortal template injection
Versions: 3.0.39
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T00:30:39.000Z