CVE-2025-70830

A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to execute arbitrary code via injecting crafted Freemarker template syntax into the SQL script field.
Configurations

No configuration.

History

No history.

Information

Published : 2026-02-17 16:20

Updated : 2026-06-17 10:03


NVD link : CVE-2025-70830

Mitre link : CVE-2025-70830

CVE.ORG link : CVE-2025-70830


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')