Skip to content
Vulnerability field guide

Server-Side Template Injection

When user input is stitched into a server-side template, the template engine becomes an interpreter for the attacker. Here is how a harmless-looking arithmetic probe escalates to full server compromise, and how to design the bug out entirely.

1 article 6 min total Overview to advanced techniques