SSTI

Notes about some basic Server Side Template Injection attack

Server Side Template Injection (SSTI) is a web exploit which takes advantage of an insecure implementation of a template engine.

Playground

Identification

Quick Identification

Template Injection Tablearrow-up-right

Tools

SSTImap

SSTImap

TInjA – the Template INJection Analyzer

TInjA – the Template INJection Analyzer

Resources

Last updated

Was this helpful?