Impact
A Server‑Side Template Injection vulnerability in the Velocity template engine configuration of the xdocreport library, versions 0.9.2 through 2.2.0, allows an attacker to supply a malicious expression that is evaluated by the engine and executed on the host system. This flaw, a code‑injection weakness (CWE‑94), can compromise confidentiality, integrity, and availability.
Affected Systems
Affected systems are applications that incorporate xdocreport v0.9.2‑v2.2.0 and use the Velocity engine with unrestricted expression evaluation. No specific vendor or product name is listed in the CNA data, and later releases beyond 2.2.0 are assumed to contain the fix.
Risk and Exploitability
With a CVSS score of 9.8 and an EPSS below 1 %, this vulnerability is critical but currently has a low probability of exploitation. It is not listed in the CISA KEV catalog. Exploitation requires processing a crafted expression by the Velocity engine, thus necessitating the application to load untrusted template data. The impact is arbitrary code execution on the host.
OpenCVE Enrichment