Template Injection can arise both through developer error, and through the intentional exposure of templates in an attempt to offer rich functionality, as commonly done by wikis, blogs, marketing applications and content management systems. Intentional template injection is such a common use-case that many template engines offer a 'sandboxed' mode for this express purpose.


Swapnil Pandya

Security Researcher and Learner in Web Penetration testing & Digital Forensics. Knowledge sharing and gaining is more focused and growing together is what I firmly believe. Also working with Inferno Infosec for betterment of cyber space and securing clients data.


