AdPortal Server-Side Template Injection Vulnerability Allowing Arbitrary Code Execution
Vulnerability
A server-side template injection vulnerability has been identified in AdPortal version 3.0.39. This vulnerability allows remote attackers to execute arbitrary code by manipulating the shippingAsBilling and firstname parameters in the updateuserinfo.html file.
Impact
Exploitation of this vulnerability allows for arbitrary code execution on the server where AdPortal is hosted.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
10.0exploitability
7.4remediation
0.0relevance
0.0threat
0.1urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
