GHSA-4pqh-3f6p-63c5 · Severity: critical — Server-Side Template Injection (SSTI) in Wirtualna Uczelnia allows an unauthenticated attacker to...
Server-Side Template Injection (SSTI) in Wirtualna Uczelnia allows an unauthenticated attacker to perform Remote Code Execution (RCE). In the endpoint redirectToUrl and parameter redirectUrlParameter, insufficient input validation permits injection of arbitrary template expressions that are executed on the server. Successful exploitation can allow an attacker to run remote commands, including establishing a reverse shell. This issue affects Wirtualna Uczelnia versions up to wu#2016.437.295#0#20260327_105545
Conclusion & alert: CVE-2026-34906 is rated Moderate Risk (57.3/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 0.93%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.38% | 0.93% | +0.55% |
| 2 | 2026-06-08 | 0.29% | 0.38% | +0.09% |
| 3 | 2026-06-02 | — | 0.29% | — |
Full EPSS history (3 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.3 | 4.0 | CRITICAL |
|
— | — | [email protected] |
GHSA-4pqh-3f6p-63c5 · Severity: critical — Server-Side Template Injection (SSTI) in Wirtualna Uczelnia allows an unauthenticated attacker to...
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||