Komm.One CMS 10.4.2.14 has a Server-Side Template Injection (SSTI) vulnerability via the Velocity template engine. It allows remote attackers to execute arbitrary code via a URL that specifies java.lang.Runtime in conjunction with getRuntime().exec followed by an OS command.
References
Configurations
No configuration.
History
25 Mar 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-94 |
21 Nov 2024, 08:59
Type | Values Removed | Values Added |
---|---|---|
References | () https://blog.munz4u.de/posts/2023/11/cve-2023-xxxxx-rce-via-ssti-in-komm.one-cms-10.4.2.14/ - |
02 Aug 2024, 18:35
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
18 Mar 2024, 02:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-18 02:15
Updated : 2025-03-25 18:15
NVD link : CVE-2024-24230
Mitre link : CVE-2024-24230
CVE.ORG link : CVE-2024-24230
JSON object : View
Products Affected
No product.
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')