Server-Side Template Injection in Dromara UJCMS Web-File-Template Endpoint
CVE-2026-78140
Key Information:
Badges
What is CVE-2026-78140?
A vulnerability exists in Dromara UJCMS versions up to 10.1.3, specifically in the update function of the WebFileTemplateController.java file. The flaw enables a server-side template injection, allowing attackers to manipulate special elements within the template engine. This vulnerability can be exploited remotely, posing a significant threat to the security of applications utilizing this endpoint. Active exploitation has been reported, making it critical for impacted users to address the issue promptly.
Affected Version(s)
UJCMS 10.1.0
UJCMS 10.1.1
UJCMS 10.1.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
