Mapfish Print: Remote Code Injection (RCE) in Dynamic table
The attacker can execute arbitrary code without being authenticated
The attacker can execute arbitrary code without being authenticated
In mapfish-print, an attacker can run an XML External Entity (XXE) attack with the provided SDL style.
In mapfish-print, a user can use the JSONP support to do a Cross-site scripting.