<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Marc-Oliver Munz</title>
		<link>https://blog.munz4u.de/</link>
		<description>Recent content on Marc-Oliver Munz</description>
		<generator>Hugo</generator>
		<language>en-us</language>
		
		
		
			<copyright>&lt;a href=&#34;https://creativecommons.org/licenses/by-nc/4.0/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;CC BY-NC 4.0&lt;/a&gt;</copyright>
		
		
			<lastBuildDate>Wed, 15 Nov 2023 14:12:02 +0100</lastBuildDate>
		
			<atom:link href="https://blog.munz4u.de/index.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>CVE-2024-24230 RCE via SSTI in Komm.One CMS 10.4.2.14</title>
				<link>https://blog.munz4u.de/posts/2023/11/cve-2024-24230-rce-via-ssti-in-komm.one-cms-10.4.2.14/</link>
				<pubDate>Wed, 15 Nov 2023 14:12:02 +0100</pubDate>
				<guid>https://blog.munz4u.de/posts/2023/11/cve-2024-24230-rce-via-ssti-in-komm.one-cms-10.4.2.14/</guid>
				<description>&lt;h2 id=&#34;tldr&#34;&gt;TL;DR&lt;a class=&#34;heading-anchor&#34; href=&#34;#tldr&#34; aria-label=&#34;Copy link to this section&#34; title=&#34;Copy link to this section&#34;&gt;#&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;I uncovered a critical Remote Code Execution vulnerability in Komm.One&amp;rsquo;s Content Management System version &lt;code&gt;10.4.2.14&lt;/code&gt;. Initially, I identified a Server-Side Template Injection (SSTI) flaw in the Velocity template engine, leading to the execution of arbitrary code and affecting several hundred sites. It is noteworthy that all vulnerable instances have now been fixed.&lt;/p&gt;&#xA;&lt;h2 id=&#34;initial-finding&#34;&gt;Initial Finding&lt;a class=&#34;heading-anchor&#34; href=&#34;#initial-finding&#34; aria-label=&#34;Copy link to this section&#34; title=&#34;Copy link to this section&#34;&gt;#&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;While examining a website, I discovered that the SSTI payload below is echoed processed in the response:&lt;/p&gt;</description>
			</item>
			<item>
				<title>CVE-2023-25295 ATO via rXSS in eVEWA3 Community</title>
				<link>https://blog.munz4u.de/posts/2023/03/cve-2023-25295-ato-via-rxss-in-evewa3-community/</link>
				<pubDate>Wed, 08 Mar 2023 12:00:00 +0100</pubDate>
				<guid>https://blog.munz4u.de/posts/2023/03/cve-2023-25295-ato-via-rxss-in-evewa3-community/</guid>
				<description>&lt;h2 id=&#34;tldr&#34;&gt;TL;DR&lt;a class=&#34;heading-anchor&#34; href=&#34;#tldr&#34; aria-label=&#34;Copy link to this section&#34; title=&#34;Copy link to this section&#34;&gt;#&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;The GRÜN eVEWA Community versions 31 to 53 were susceptible to a reflected Cross-Site Scripting (rXSS) vulnerability in the login form. This vulnerability enables attackers to acquire escalated privileges by submitting a crafted request to the login panel. To address this issue, a security patch labeled &amp;ldquo;H1&amp;rdquo; has been applied across versions 31 to 53.&lt;/p&gt;&#xA;&lt;h2 id=&#34;initial-findings&#34;&gt;Initial Findings&lt;a class=&#34;heading-anchor&#34; href=&#34;#initial-findings&#34; aria-label=&#34;Copy link to this section&#34; title=&#34;Copy link to this section&#34;&gt;#&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;During my investigation of a domain, I stumbled upon a GRÜN eVEWA site. During my examination of the endpoints, I identified vulnerable rXSS file parameters in the following locations:&lt;/p&gt;</description>
			</item>
			<item>
				<title>Datenschutzerklärung</title>
				<link>https://blog.munz4u.de/datenschutz/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://blog.munz4u.de/datenschutz/</guid>
				<description>&lt;div class=&#34;lang-block&#34; data-lang=&#34;de&#34; lang=&#34;de&#34;&gt;&#xA;&lt;p&gt;Diese Website ist eine statische Seite, die mit dem Generator Hugo erstellt wird. Sie&#xA;verwendet &lt;strong&gt;keine Cookies&lt;/strong&gt;, &lt;strong&gt;kein Tracking&lt;/strong&gt;, &lt;strong&gt;keine Analyse- oder Werbedienste&lt;/strong&gt; und&#xA;bindet keine externen Inhalte (z. B. Schriftarten, Videos) nach, die beim Aufruf&#xA;automatisch Daten an Dritte übertragen. Personenbezogene Daten werden durch den Betreiber&#xA;nicht aktiv erhoben.&lt;/p&gt;&#xA;&lt;h2 id=&#34;verantwortlicher&#34;&gt;Verantwortlicher&lt;a class=&#34;heading-anchor&#34; href=&#34;#verantwortlicher&#34; aria-label=&#34;Copy link to this section&#34; title=&#34;Copy link to this section&#34;&gt;#&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;Marc-Oliver Munz&lt;br&gt;&#xA;Muselgasse 1&lt;br&gt;&#xA;72639 Neuffen&lt;br&gt;&#xA;Deutschland&lt;/p&gt;&#xA;&lt;p&gt;E-Mail: &lt;a class=&#34;email-link&#34; href=&#34;#&#34; rel=&#34;nofollow&#34; data-e=&#34;c2VjdXJpdHlAbXVuejR1LmRl&#34;&gt;security [at] munz4u [dot] de&lt;/a&gt;&lt;/p&gt;</description>
			</item>
			<item>
				<title>Impressum</title>
				<link>https://blog.munz4u.de/impressum/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://blog.munz4u.de/impressum/</guid>
				<description>&lt;div class=&#34;lang-block&#34; data-lang=&#34;de&#34; lang=&#34;de&#34;&gt;&#xA;&lt;p&gt;Angaben gemäß § 5 DDG (Digitale-Dienste-Gesetz).&lt;/p&gt;&#xA;&lt;h2 id=&#34;diensteanbieter&#34;&gt;Diensteanbieter&lt;a class=&#34;heading-anchor&#34; href=&#34;#diensteanbieter&#34; aria-label=&#34;Copy link to this section&#34; title=&#34;Copy link to this section&#34;&gt;#&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;Marc-Oliver Munz&lt;br&gt;&#xA;Muselgasse 1&lt;br&gt;&#xA;72639 Neuffen&lt;br&gt;&#xA;Deutschland&lt;/p&gt;&#xA;&lt;h2 id=&#34;kontakt&#34;&gt;Kontakt&lt;a class=&#34;heading-anchor&#34; href=&#34;#kontakt&#34; aria-label=&#34;Copy link to this section&#34; title=&#34;Copy link to this section&#34;&gt;#&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;E-Mail: &lt;a class=&#34;email-link&#34; href=&#34;#&#34; rel=&#34;nofollow&#34; data-e=&#34;c2VjdXJpdHlAbXVuejR1LmRl&#34;&gt;security [at] munz4u [dot] de&lt;/a&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;umsatzsteuer-identifikationsnummer&#34;&gt;Umsatzsteuer-Identifikationsnummer&lt;a class=&#34;heading-anchor&#34; href=&#34;#umsatzsteuer-identifikationsnummer&#34; aria-label=&#34;Copy link to this section&#34; title=&#34;Copy link to this section&#34;&gt;#&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;Umsatzsteuer-Identifikationsnummer gemäß § 27a Umsatzsteuergesetz:&#xA;&lt;span class=&#34;obf&#34; data-o=&#34;REUzNjQzOTQyOTI=&#34;&gt;DE 364 394 292&lt;/span&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;verantwortlich-für-den-inhalt-nach--18-abs-2-mstv&#34;&gt;Verantwortlich für den Inhalt nach § 18 Abs. 2 MStV&lt;a class=&#34;heading-anchor&#34; href=&#34;#verantwortlich-f%c3%bcr-den-inhalt-nach--18-abs-2-mstv&#34; aria-label=&#34;Copy link to this section&#34; title=&#34;Copy link to this section&#34;&gt;#&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;Marc-Oliver Munz&lt;br&gt;&#xA;Muselgasse 1&lt;br&gt;&#xA;72639 Neuffen&lt;br&gt;&#xA;Deutschland&lt;/p&gt;</description>
			</item>
	</channel>
</rss>
