Improper Neutralization of Special Elements Used in a Template Engine in OneDev - CVE-2021-21244
Published: January 12, 2021 / Updated: May 5, 2026
OneDev
OneDev
Description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to server-side template injection in ValidQueryParamsValidator when handling unexpected query parameters in REST requests. A remote attacker can send a specially crafted query parameter to execute arbitrary code.
The issue is triggered before authentication or authorization checks are enforced.