| Details | |
|---|---|
| Alert ID | 90036 |
| Alert Type | Active |
| Status | release |
| Risk | High |
| CWE | 1336 |
| WASC | 20 |
| Technologies Targeted | All |
| Tags |
API_2023_API10 CWE-1336 OUT_OF_BAND OWASP_2017_A01 OWASP_2021_A03 OWASP_2025_A05 POLICY_API POLICY_DEV_FULL POLICY_PENTEST POLICY_QA_FULL POLICY_SEQUENCE TEST_TIMING WSTG-V42-INPV-18 |
| More Info |
Scan Rule Help |
Summary
When the user input is inserted in the template instead of being used as argument in rendering is evaluated by the template engine. Depending on the template engine it can lead to remote code execution.