An Assessment of the Overlooked Dangers of Template Engines

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Pisu, Lorenzo, Maiorca, Davide, Giacinto, Giorgio
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915826104270848
author Pisu, Lorenzo
Maiorca, Davide
Giacinto, Giorgio
author_facet Pisu, Lorenzo
Maiorca, Davide
Giacinto, Giorgio
contents Template engines play a pivotal role in modern web application development by enabling the dynamic rendering of content, products, and user interfaces. Today, they are essential for any website that handles dynamic data, from e-commerce to social media. However, their widespread adoption also makes them attractive targets for attackers seeking to exploit vulnerabilities and gain unauthorized access to web servers. This paper presents a comprehensive assessment of the risks associated with template engines, with a particular focus on the consequences of Server-Side Template Injection (SSTI) and the ease with which such vulnerabilities can escalate to Remote Code Execution (RCE), a critical security concern in web application development.
format Preprint
id arxiv_https___arxiv_org_abs_2405_01118
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle An Assessment of the Overlooked Dangers of Template Engines
Pisu, Lorenzo
Maiorca, Davide
Giacinto, Giorgio
Cryptography and Security
Template engines play a pivotal role in modern web application development by enabling the dynamic rendering of content, products, and user interfaces. Today, they are essential for any website that handles dynamic data, from e-commerce to social media. However, their widespread adoption also makes them attractive targets for attackers seeking to exploit vulnerabilities and gain unauthorized access to web servers. This paper presents a comprehensive assessment of the risks associated with template engines, with a particular focus on the consequences of Server-Side Template Injection (SSTI) and the ease with which such vulnerabilities can escalate to Remote Code Execution (RCE), a critical security concern in web application development.
title An Assessment of the Overlooked Dangers of Template Engines
topic Cryptography and Security
url https://arxiv.org/abs/2405.01118