References https://www.cnblogs.com/pursue-security/p/17665454.html https://stack.chaitin.com/techblog/detail/208 https://blog.csdn.net/xiayu729100940/article/details/136847745 https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/webapp/JeecgBoot-SSTI-CVE-2023-4450.md https://blog.certcube.com/jeecgboot-jimureport-ssti-rce-cve-2023-4450/ https://zhuanlan.zhihu.com/p/1888282077968958078 https://qkl.seebug.org/vuldb/ssvid-99746 https://c0olw.github.io/2023/08/15/JeecgBoot-SSTI%E4%BB%A5%E5%8F%8AJDBC-RCE/ https://cloud.tencent.com/developer/news/1159838 https://juejin.cn/post/7267434484504739892 https://nic.xaut.edu.cn/info/11846/332381.htm https://zhi.oscs1024.com/4711.html https://xie.infoq.cn/article/6774540f34bcc89e7e482a246 https://whoopsunix.com/docs/java/named%20module/ https://www.ctfiot.com/157621.html https://rivers.chaitin.cn/blog/cq70jnqp1rhtmlvvdp0g https://blog.csdn.net/qq_45240382/article/details/140508539 https://comate.baidu.com/zh/page/ec8rk54s6yz https://blog.csdn.net/lll78/article/details/155589774 https://dev.rivers.ctopt.cn/s?keywords=%E9%9D%B6%E5%9C%BA
Related Vulnerabilities用友 GRP-U8Cloud /jmreport/queryFieldBySql Freemarker 命令执行漏洞PoCCVE-2024-41667: OpenAM<=15.0.3 FreeMarker - Template InjectionPoCfreemarker-sandbox-bypass-ssti: Freemarker < 2.3.30 Sandbox Bypass - Server Side Template InjectionPoCfreemarker-oob: Freemarker 2.3.33 - Out of Band Template Injection万户OA freemarkerQa 接口存在远程命令执行漏洞PoCJeecg-Boot Freemarker /jmreport/queryFieldBySql 模版注入漏洞