CVE-2026-3725 | 1024-lab/lab1024 SmartAdmin up to 3.29 FreeMarker Template MailService.java freemarkerResolverContent template_content special elements used in a template engine (EUVD-2026-10228)
A vulnerability labeled as critical has been found in 1024-lab/lab1024 SmartAdmin up to 3.29. Affected by this issue is the function freemarkerResolverContent of the file sa-base/src/main/java/net/lab1024/sa/base/module/support/mail/MailService.java of the component FreeMarker Template Handler. Executing a manipulation of the argument template_content can lead to improper neutralization of special elements used in a template engine.
This vulnerability is tracked as CVE-2026-3725. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.