
Conversor from @hackthebox_eu features XSLT injection and os.path.join abuse for file write, and CVE-2024-48990 in needrestart (plus a config GTFObin) for root. https://0xdf.gitlab.io/2026/03/21/htb-conversor.html
Post summary
The post discloses a CVE‑2024‑48990 flaw involving XSLT injection and file‑write via os.path.join abuse, with details pointing to a PoC hosted on the linked blog.


