Executive brief
Sanluan PublicCMS, a content management system, contains a vulnerability in its template processing API. An attacker with low-level access can bypass security restrictions to run unauthorized commands or view sensitive server information, such as file paths and system configurations. This could lead to further exploitation of the server or unauthorized access to internal data.
Technical details
A Server-Side Template Injection (SSTI) vulnerability exists in the `templateResult` API of Sanluan PublicCMS 5.202506.d. The flaw is located in the `execute` function of `TemplateResultDirective.java`, where user-provided `templateContent` is evaluated as a FreeMarker template using the full web configuration. While direct HTTP access to sensitive directives is protected by `authorizedApis` checks, these checks are bypassed when directives are invoked internally via a template. An authenticated attacker with a low-privilege app token can exploit this to execute internal directives like `tools.systemProperties` or `tools.disk`, leading to the disclosure of server-side information. No official patch has been released by the vendor as of the disclosure date.
Affected products
- Sanluan PublicCMS 5.202506.d
Timeline
- 2026-05-17: disclosed: Vulnerability details and PoC published via VulDB and NVD.
- 2026-05-17: advisory