OneBlog Template Injection Vulnerability in Version 2.3.6 Allowing Code Execution

Vulnerability

A template injection vulnerability has been identified in OneBlog version 2.3.6, specifically within the template management section. This issue arises from the 'spring-boot-starter-freemarker' component, which lacks proper rule restrictions, enabling arbitrary code execution.

Impact

Exploitation of this vulnerability allows for template injection, which can lead to arbitrary code execution on the server.

Reproduction

To reproduce this vulnerability, reference the 'spring-boot-starter-freemarker' component in the 'blog-core/pom.xml' file. In the template management section of the backend, locate the 'TM_SITEMAP_HTML' file and inject the proof of concept (POC) payload, which includes commands to execute, such as opening the calculator application or reading the '/etc/passwd' file. After saving the injection, the vulnerability can be triggered by accessing the sitemap.html file, either through the homepage or directly via the URL.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
7.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.