SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  listmonk Sprig Server-Side Template Injection 2

Category: WEB-ATTACKS      

The env and expandenv template functions which is enabled by default in Sprig enables capturing of env variables on the host. While this may not be a problem on single-user (super admin) installations, on multi-user installations, this allows non-super-admin users with campaign or template permissions to use the {{ env }} template expression to capture sensitive environment variables.


Relevant Information