CVE-2025-60355
9.8CRITICALzhangyd-c OneBlog before 2.3.9 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.
Veröffentlicht: 10/28/2025Aktualisiert: 1/8/2026
Beschreibung
zhangyd-c OneBlog before 2.3.9 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.
KI-AnalyseKI-gestützt
Betroffene Produkte
zhydoneblog
Referenzen
- https://github.com/line2222/vuln/issues/4ExploitIssue TrackingThird Party Advisory