Exploitation Summary
EIP tracks 1 public exploit for CVE-2025-64087. PoCs published by AT190510-Cuong.
AI-analyzed exploit summary This repository contains a detailed technical analysis of CVE-2025-64087, a Server-Side Template Injection (SSTI) vulnerability in XDocReport's FreeMarker engine. It includes root cause analysis, exploitation steps, and mitigation details, demonstrating a deep understanding of the vulnerability.
Description
A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2.1.0 allows attackers to execute arbitrary code via injecting crafted template expressions.
Exploits (1)
This repository contains a detailed technical analysis of CVE-2025-64087, a Server-Side Template Injection (SSTI) vulnerability in XDocReport's FreeMarker engine. It includes root cause analysis, exploitation steps, and mitigation details, demonstrating a deep understanding of the vulnerability.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H