CVE-2024-24230: Komm.one CMS
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
Komm.One CMS 10.4.2.14 has a Server-Side Template Injection (SSTI) vulnerability via the Velocity template engine. It allows remote attackers to execute arbitrary code via a URL that specifies java.lang.Runtime in conjunction with getRuntime().exec followed by an OS command.
Affected products
- Komm.one CMS: version 10.4.2.14 only
Published 2024-03-18. Last modified 2026-06-17.