JavaServer Pages evaluates the unified expression language in ${...}, resolving names against the page, request, session, and application scopes through the pageContext. The expression is evaluated immediately as the page renders. Injection appears when request data lands inside an expression the container then evaluates: a parameter reflected into a ${...} context, a value passed to application.evaluate through the JSP ExpressionFactory, or a tag attribute built from user input. The container runs the resulting EL with the page's scopes in reach.
The reachable surface matches the servlet EL grammar. The implicit scope objects (param, header, sessionScope, requestScope, applicationScope, pageContext) expose the attributes an access decision reads, and from EL 2.2 onward method invocation reaches reflection and the host runtime.
- Authorization bypass: reaching the scope maps and
pageContextto read and force the values a check depends on. - Code execution: using method invocation and reflection to reach a script engine or
ProcessBuilder.