Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Komm.One CMS 10.4.2.14 has a Server-Side Template Injection (SSTI) vulnerability via the Velocity template engine. It allows remote attackers to execute arbitrary code via a URL that specifies java.lang.Runtime in conjunction with getRuntime().exec followed by an OS command.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Komm.One CMS 安全漏洞
Vulnerability Description
Komm.One CMS是德国Komm.One公司的一款客户服务管理软件。 Komm.One CMS 10.4.2.14版本存在安全漏洞,该漏洞源于允许远程攻击者通过指定 java.lang.Runtime 的 URL 与 getRuntime().exec 结合使用来执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A