opensagres / xdocreport

XDocReport means XML Document reporting. It's Java API to merge XML document created with MS Office (docx) or OpenOffice (odt), LibreOffice (odt) with a Java model to generate report and convert it if you need to another format (PDF, XHTML...).
https://github.com/opensagres/xdocreport
1.19k stars 368 forks source link

Velocity Template Injection #676

Open dienuet opened 2 weeks ago

dienuet commented 2 weeks ago

Hi team, I am not sure that creating Velocity template in docx is intended or security issue. I crafted a payload that successfully executes an OS command. If you need more information,pls contact me: phamdien95hy@gmail.com