S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Feb 9, 2025

CVE-2024-46507 Scanner

CVE-2024-46507 Scanner - Server Side Template Injection (SSTI) vulnerability in Yeti Platform

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.4k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-46507
7.3
CVSShigh
Exploitable remotely over the internet · no authentication required.

A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows attackers to execute code on the application server.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Yeti Platform is primarily utilized by security researchers and threat intelligence teams. It aids in the analysis and tracking of cyber threats and indicators of compromise. Organizations leverage the platform for its comprehensive data correlation and visualization capabilities. Yeti Platform's intuitive user interface makes it accessible for both seasoned analysts and novices alike. Its wide range of integrations allows ease of connectivity with other security tools.

Server Side Template Injection (SSTI) vulnerabilities occur when an application incorrectly handles user input for server-side templates. This specific SSTI vulnerability in Yeti Platform can be exploited by malicious actors with valid credentials. They can inject malicious template expressions into the server, which are then executed. This can potentially allow for arbitrary command execution on the host server. As a result, it poses a critical security risk.

This vulnerability exists due to the failure to sanitize inputs in the application's templating engine. Attackers can craft special payloads and inject them via HTTP POST requests to the /api/v2/templates/ endpoint. The vulnerability resides in the server’s evaluation of template expressions without proper input validation. If exploited, the injected expressions execute within the server's context. The flaw allows various privileges depending on the server’s user execution context.

Exploiting this vulnerability can lead to severe consequences. Attackers may gain unauthorized access to sensitive data hosted on the server. Malicious commands could be executed, causing service disruptions or unauthorized server modifications. Ultimately, this insecurity could result in full server compromise and data exfiltration. There is also potential for the introduction of further vulnerabilities through manipulated updates or configurations.

REFERENCES

Solution Advice
  • Upgrade to Yeti Platform version 2.1.12 or later.
  • Implement stronger input validation and sanitation for template expressions.
  • Regularly audit and deploy security updates for the platform.
  • Restrict access to the platform to trusted users via multi-factor authentication.
  • Monitor logs for unusual activity indicative of attempted injections.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.