Product
An authenticated administrator can exploit a server-side template injection (SSTI) vulnerability in GeoServer's FreeMarker engine to execute arbitrary OS commands and perform unauthorized file operations.