CVE-2026-3725 Details
Description
A flaw has been found in 1024-lab/lab1024 SmartAdmin up to 3.29. Affected by this issue is the function freemarkerResolverContent of the file sa-base/src/main/java/net/lab1024/sa/base/module/support/mail/MailService.java of the component FreeMarker Template Handler. Executing a manipulation of the argument template_content can lead to improper neutralization of special elements used in a template engine. The attack can be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A server-side template injection vulnerability has been identified in 1024-lab/lab1024 SmartAdmin versions through 3.29. This issue arises in the email template rendering functionality, which utilizes the Apache FreeMarker template engine. The vulnerability is located in the 'freemarkerResolverContent' function of 'MailService.java'. An attacker with access to modify the 'template_content' field in the 't_mail_template' table can inject arbitrary FreeMarker expressions. These injected expressions are executed on the server when the email is sent, potentially leading to remote code execution with the application's server privileges, and allowing complete system compromise.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vuldb.com/?ctiid.349703 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.349703 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.766459 | [email protected] | Third Party AdvisoryVDB Entry |
| https://www.notion.so/SmartAdmin-Server-Side-Template-Injection-SSTI-in-Email-Template-Rendering-310ea92a3c418087ac63ec8e5a061b62 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1336 | Improper Neutralization of Special Elements Used in a Template Engine | [email protected] |
| CWE-791 | Incomplete Filtering of Special Elements | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| lab1024 smartadmin | <= 3.29 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Mar 13, 2026 | Initial Analysis | [email protected] |
| Mar 8, 2026 | New CVE Received | [email protected] |