
CVE-2022-40634: FreeMarker Server-Side Template Injection in CrafterCMS
By inserting malicious content in a FTL template, an attacker may perform SSTI (Server-Side Template Injection) attacks, which can leverage FreeMarker exposed objects to bypass restrictions and obtain RCE (Remote Code Execution).
The vendor's disclosure and fix for this vulnerability can be found here.
This vulnerability requires:
More details and the exploitation process can be found in this PDF.
Initial vulnerability (CVE-2020-25803) and blogpost by Alvaro "pwntester" Munoz that inspired the SSTI research and finding of this vulnerability.