<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Ssti on Marc-Oliver Munz</title>
		<link>https://blog.munz4u.de/tags/ssti/</link>
		<description>Recent content in Ssti on Marc-Oliver Munz</description>
		<generator>Hugo</generator>
		<language>en-us</language>
		
		
		
			<copyright>&lt;a href=&#34;https://creativecommons.org/licenses/by-nc/4.0/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;CC BY-NC 4.0&lt;/a&gt;</copyright>
		
		
			<lastBuildDate>Wed, 15 Nov 2023 14:12:02 +0100</lastBuildDate>
		
			<atom:link href="https://blog.munz4u.de/tags/ssti/index.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>CVE-2024-24230 RCE via SSTI in Komm.One CMS 10.4.2.14</title>
				<link>https://blog.munz4u.de/posts/2023/11/cve-2024-24230-rce-via-ssti-in-komm.one-cms-10.4.2.14/</link>
				<pubDate>Wed, 15 Nov 2023 14:12:02 +0100</pubDate>
				<guid>https://blog.munz4u.de/posts/2023/11/cve-2024-24230-rce-via-ssti-in-komm.one-cms-10.4.2.14/</guid>
				<description>&lt;style&gt;&#xA;  table {&#xA;    width: 100%;&#xA;    border-collapse: collapse;&#xA;    margin-bottom: 20px; /* Optional: Add some spacing between the table and other elements */&#xA;  }&#xA;&#xA;  th, td {&#xA;    padding: 10px;&#xA;    border: 1px solid #ddd;&#xA;    text-align: left;&#xA;  }&#xA;&#xA;  @media screen and (max-width: 600px) {&#xA;    th, td {&#xA;      display: block;&#xA;      width: 100%;&#xA;      box-sizing: border-box;&#xA;    }&#xA;  }&#xA;&lt;/style&gt;&#xA;&lt;h2 id=&#34;tldr&#34;&gt;TL;DR&lt;/h2&gt;&#xA;&lt;p&gt;I uncovered a critical Remote Code Execution vulnerability in Komm.One&amp;rsquo;s Content Management System version &lt;code&gt;10.4.2.14&lt;/code&gt;. Initially, I identified a Server-Side Template Injection (SSTI) flaw in the Velocity template engine, leading to the execution of arbitrary code and affecting several hundred sites. It is noteworthy that all vulnerable instances have now been fixed.&lt;/p&gt;</description>
			</item>
	</channel>
</rss>
