CVE-2025-64087

A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2.1.0 allows attackers to execute arbitrary code via injecting crafted template expressions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:opensagres:xdocreport:*:*:*:*:*:*:*:*

History

03 Feb 2026, 21:49

Type Values Removed Values Added
CPE cpe:2.3:a:opensagres:xdocreport:*:*:*:*:*:*:*:*
References () https://github.com/AT190510-Cuong/CVE-2025-64087-SSTI- - () https://github.com/AT190510-Cuong/CVE-2025-64087-SSTI- - Broken Link
References () https://github.com/opensagres/xdocreport - () https://github.com/opensagres/xdocreport - Product
References () https://github.com/opensagres/xdocreport/pull/705 - () https://github.com/opensagres/xdocreport/pull/705 - Issue Tracking, Third Party Advisory
References () https://hackmd.io/@cuongnh/BJEnw7SAlg - () https://hackmd.io/@cuongnh/BJEnw7SAlg - Permissions Required
References () https://hackmd.io/@cuongnh/SkQvhEf0lx - () https://hackmd.io/@cuongnh/SkQvhEf0lx - Permissions Required
First Time Opensagres
Opensagres xdocreport

Information

Published : 2026-01-20 16:16

Updated : 2026-02-03 21:49


NVD link : CVE-2025-64087

Mitre link : CVE-2025-64087

CVE.ORG link : CVE-2025-64087


JSON object : View

Products Affected

opensagres

  • xdocreport
CWE
CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine