Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

cve-2023-4596 nonce #1

Closed
scotch123 opened this issue Sep 1, 2023 · 4 comments
Closed

cve-2023-4596 nonce #1

scotch123 opened this issue Sep 1, 2023 · 4 comments
Assignees

Comments

@scotch123
Copy link

Only get this error: [-] Could not extract forminator_nonce

What's wrong ? ..

@E1A
Copy link
Owner

E1A commented Sep 2, 2023

Hi there!

This exploit only works when a link is provided of the exact page where the file upload is enabled with Forminator. When a link is provided with just the domain or a page that is not running a file upload on it, it spits out the error you received. This is because it exports the forminator_nonce from the provided URL and if this page is not running Forminator or the Forminator file upload, it can't find it and can't use it.
I'll change the script and readme to make it more clear.

If you did provide a valid URL, could you answer the following questions for me to determine if something is wrong with the script?

  1. Did you put the exact link of the page with file upload enabled in the command? File upload must of course be provided by Forminator which you can check by finding the string "forminator-field-upload" or "forminator-field-post-image-postdata" in the source code of the site. A full link, for example, looks like this: http://127.0.0.1:8000/?p=7
  2. Did you use -v to check if Forminator is vulnerable?

@E1A E1A self-assigned this Sep 2, 2023
@E1A
Copy link
Owner

E1A commented Sep 10, 2023

Ping

@E1A
Copy link
Owner

E1A commented Sep 16, 2023

Close since no response was submitted in 2 weeks

@E1A E1A closed this as completed Sep 16, 2023
@forme9
Copy link

forme9 commented Nov 13, 2023

hi, Have the above issues been resolved?
How to find the exact link to the page that supports file uploads in Forminator?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants