> For the complete documentation index, see [llms.txt](https://evanluke.gitbook.io/appsec/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://evanluke.gitbook.io/appsec/injection/template-injection/template-injection-examples.md).

# Server-Side Template Injection Writeups

### Uber - Template Injection Python RCE&#x20;

{% embed url="<https://hackerone.com/reports/125980>" %}

Personal Blog Post:

{% embed url="<http://blog.orange.tw/2016/04/bug-bounty-uber-ubercom-remote-code_7.html>" %}

Orange Tsai discovered a Template Injection on rider.uber.com domain. Changing user name to the payload `{{ '7'*7 }}` will return the value `'7777777'`in the followup email "Your Uber account information has been updated" notification.&#x20;

![Email notification with the executed template injection payload showing execution on the backend server](https://4166910944-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6GgEQGJyt_GNdNEMG7%2F-MOrBerXueX59FX1cUv0%2F-MOxT48cPts-BRWkblrz%2FScreen%20Shot%202020-12-19%20at%207.06.34%20PM.png?alt=media\&token=46b7b53f-1008-44f6-b274-18391c55f810)

```
//Payloads used 
{{ '7'*7 }}
{{ [].class.base.subclasses() }} # get all classes
{{''.class.mro()[1].subclasses()}}
{%for c in [1,2,3] %}{{c,c,c}}{% endfor %}
```

### WordPress - XSS&#x20;

{% embed url="<https://hackerone.com/reports/250837>" %}

The billing\_first\_name body parameter on the POST /wp-admin/admin-ajax.php route is vulnerable to Template Injection which allows Stored XSS on the account page.&#x20;

![HTTP POST request with Template Injection payload in the billing\_first\_name body parameter](https://4166910944-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6GgEQGJyt_GNdNEMG7%2F-MOrBerXueX59FX1cUv0%2F-MOxOwmzg_OQxYdOKZ_q%2FScreen%20Shot%202020-12-19%20at%206.47.06%20PM.png?alt=media\&token=35364706-e652-4411-86f6-3b2b5a358281)

The Stored XSS is returned on the accounts page <https://mercantile.wordpress.org/my\\_account>:

![Stored XSS Alert payload executed on the account page](https://4166910944-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6GgEQGJyt_GNdNEMG7%2F-MOrBerXueX59FX1cUv0%2F-MOxQWerqWf8EHZw6rFJ%2FScreen%20Shot%202020-12-19%20at%206.47.18%20PM.png?alt=media\&token=afe282ff-d800-4d1e-b0be-7ac6c41c3e6d)

### Unikrn - Smarty Template&#x20;

{% embed url="<https://hackerone.com/reports/164224>" %}

Researcher discovered on of the fields on the user invite page was vulnerable to Template Injection. Upon entering {7\*7} into all the fields for registration a verbose error message is returned in the email message notification, revealing a Smarty Template engine message.&#x20;

![Email response for user invite with {7\*7} entered as payload ](https://4166910944-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6GgEQGJyt_GNdNEMG7%2F-MOrBerXueX59FX1cUv0%2F-MOxMJEtcj6dt9H-TUcN%2FScreen%20Shot%202020-12-19%20at%206.29.14%20PM.png?alt=media\&token=a73ebb82-3473-4e69-b072-cfd88aaf7740)

Further exploited using a php payload to extract the /etc/passwd file:&#x20;

```
{php}$s = file_get_contents('/etc/passwd',NULL, NULL, 0, 100); var_dump($s);{/php}
```

![Contents of /etc/passwd file returned in noreply email ](https://4166910944-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6GgEQGJyt_GNdNEMG7%2F-MOrBerXueX59FX1cUv0%2F-MOxN_LeoNj3gpQ_xhy0%2FScreen%20Shot%202020-12-19%20at%206.42.35%20PM.png?alt=media\&token=064bccfc-e4b4-427e-8ef2-97665f3642c9)

###
