Other nomination
Room for Escape: Scribbling Outside the Lines of Template Security
Templates that untrusted users may edit break out of their sandboxes: SharePoint's safe-mode page parser is fooled by delayed data binding into parsing a user site page as a trusted application page, and Java engines such as FreeMarker, Velocity and Jinjava are escaped through objects left reachable in the template context. The result is remote code execution as an unprivileged CMS user.
Record
- Researcher
- Oleksandr Mirosh and Alvaro Muñoz
- Format
- Whitepaper
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Oleksandr Mirosh and Alvaro Muñoz, first published at the original source. Preserved copies are kept so the citation survives its host.