{ "id": "CVE-2024-24230", "sourceIdentifier": "cve@mitre.org", "published": "2024-03-18T02:15:06.123", "lastModified": "2024-03-18T12:38:25.490", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "Komm.One CMS 10.4.2.14 has a Server-Side Template Injection (SSTI) vulnerability via the Velocity template engine. It allows remote attackers to execute arbitrary code via a URL that specifies java.lang.Runtime in conjunction with getRuntime().exec followed by an OS command." }, { "lang": "es", "value": "Komm.One CMS 10.4.2.14 tiene una vulnerabilidad de inyecci\u00f3n de plantilla del lado del servidor (SSTI) a trav\u00e9s del motor de plantillas Velocity. Permite a atacantes remotos ejecutar c\u00f3digo arbitrario a trav\u00e9s de una URL que especifica java.lang.Runtime junto con getRuntime().exec seguido de un comando del sistema operativo." } ], "metrics": {}, "references": [ { "url": "https://blog.munz4u.de/posts/2023/11/cve-2023-xxxxx-rce-via-ssti-in-komm.one-cms-10.4.2.14/", "source": "cve@mitre.org" } ] }