For the complete documentation index, see llms.txt. This page is also available as Markdown.

Server Side Template Injection

Template injection allows an attacker to include template code into an existing (or not) template. A template engine makes designing HTML pages easier by using static template files which at runtime replaces variables/placeholders with actual values in the HTML pages.


Cheatsheet:

https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Server Side Template Injection/README.md

Python script for Java encoder:

Python SSTI RCE

Last updated