zhangyd-c OneBlog <2.3.9 - Server-Side Template Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-60355. PoCs published by exploitintel.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2025-60355, a critical Server-Side Template Injection (SSTI) vulnerability in OneBlog. The exploit leverages FreeMarker's unsafe class resolution to achieve remote code execution via crafted template injection.
Description
zhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.
Exploits (1)
This repository contains a functional exploit for CVE-2025-60355, a critical Server-Side Template Injection (SSTI) vulnerability in OneBlog. The exploit leverages FreeMarker's unsafe class resolution to achieve remote code execution via crafted template injection.
References (1)
Related Analysis
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H