Netaxis API Orchestrator (APIO) before 0.19.3 allows server side template injection (SSTI).
CVSS Metrics