On this page

Atomicorp WAF Rule 340130

Rule Summary

  • Rule ID: 340130
  • Status: Active
  • Alert message: Atomicorp.com WAF Rules: AngularJS client side template injection detected
  • Observed CWEs: CWE-22 (1), CWE-74 (1), CWE-79 (3), CWE-89 (1), CWE-94 (2), CWE-95 (2), CWE-287 (1), CWE-913 (1), CWE-1336 (1)
  • Revision: 8
  • Rule severity: Critical
  • Phase: 2 (request body)
  • Request surfaces: Request cookies, Request argument names, Request arguments, JSON request data, SOAP request data, XML request data
  • Rule action: deny
  • HTTP status: 403
  • Public tags: attack-xss
  • Logging: log, auditlog

Description

This rule detects behavior identified by its current alert as “AngularJS client side template injection detected” in the request cookies, request argument names, request arguments, JSON request data, SOAP request data, XML request data. It evaluates during the request body phase and denies matching traffic with HTTP status 403.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

CVEVulnerabilityProductCVSSSeverity
CVE-2021-24527Profile Builder < 3.4.9 - Improper Authenticationprofile builder9.8 (v3.1)Critical
CVE-2023-48084Nagios XI < 5.11.3 - SQL Injectionnagios xi9.8 (v3.1)Critical
CVE-2024-21650XWiki < 4.10.20 - Remote code executionxwiki9.8 (v3.1)Critical
CVE-2026-28496FOSSBilling - Server-Side Template InjectionFOSSBilling9.4 (v4.0)Critical
CVE-2023-37462XWiki Platform - Remote Code Executionxwiki8.8 (v3.1)High
CVE-2025-68613n8n - Remote Code Execution via Expression Injectionn8n8.8 (v3.1)High
CVE-2024-46507Yeti Platform < 2.1.12 - Server-Side Template Injection to RCEyeti7.3 (v3.1)High
CVE-2024-51483Changedetection.io <= 0.47.4 - Path Traversalchangedetection6.9 (v4.0)Medium
CVE-2022-28290WordPress Country Selector <1.6.6 - Cross-Site Scriptingwordpress country selector6.1 (v3.1)Medium
CVE-2023-34537Hoteldruid 3.0.5 - Cross-Site Scriptinghoteldruid5.4 (v3.1)Medium
CVE-2024-34061Changedetection.io <=v0.45.21 - Cross-Site Scriptingchangedetection.io4.3 (v3.1)Medium

Observed CWEs

These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.

CWERelated Published CVEs
CWE-22CVE-2024-51483
CWE-74CVE-2023-37462
CWE-79CVE-2022-28290 , CVE-2023-34537 , CVE-2024-34061
CWE-89CVE-2023-48084
CWE-94CVE-2024-21650 , CVE-2024-46507
CWE-95CVE-2024-21650 , CVE-2023-37462
CWE-287CVE-2021-24527
CWE-913CVE-2025-68613
CWE-1336CVE-2026-28496