
just rooted HTB Editor 🎯 full chain: XWiki SSTI RCE → credential reuse → ndsudo PATH hijacking for root. CVE-2025-24893 + CVE-2024-32019.https://labs.hackthebox.com/achievement/machine/3216229/684 #HackTheBox #HachTheBoxOndo #HTB #CyberSecurity #EthicalHacking #InfoSec #PenTesting
Post summary
The tweet outlines a HackTheBox challenge where the author leveraged an XWiki SSTI RCE to gain root via credential reuse and PATH hijacking, citing CVE‑2025‑24893 and CVE‑2024‑32019, but provides no PoC, exploit code, patch, or evidence of active exploitation.
