A penetration test found that an administrator-editable password reset email template in a Java-based application was vulnerable to server-side template injection (SSTI), allowing attacker-supplied expressions such as ${7*7} to be evaluated on the server. Further testing showed the template engine exposed access to Java classes, reflection, system properties, and environment variables on the underlying Windows host, turning a routine customization feature into a path for deeper server compromise.
The testers escalated the flaw to remote code execution by invoking Java runtime methods from the template context and verified execution through a Burp Collaborator DNS callback; they also retrieved command output directly and observed whoami returning nt authority\local service. The findings align with established SSTI research showing that unsafe template rendering can expose application internals and enable arbitrary code execution when template restrictions, input validation, and runtime sandboxing are inadequate.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
PortSwigger published research on server-side template injection, establishing the vulnerability class referenced by later work. The reference identifies this publication date explicitly.
The testers invoked `java.lang.Runtime.getRuntime().exec()` through the template injection flaw and confirmed command execution with a Burp Collaborator DNS interaction. They also retrieved direct command output with a Java Scanner payload, with `whoami` returning `nt authority\local service`.
Further probing with payloads such as `${''.getClass()}` and `forName('java.lang.System')` exposed Java reflection and allowed retrieval of system properties and environment variables, revealing the server was running on Windows. This demonstrated that the template engine exposed sensitive runtime access beyond simple expression evaluation.
During a penetration test, testers found that an administrator-editable password reset email template evaluated `${7*7}` as `49`, confirming server-side template injection in a Java-based application used for document distribution and communications. The content does not explicitly anchor when the test occurred.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.