Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Auxiliary module of CVE-2019-18818 #16168

Open
WackyHacker opened this issue Feb 10, 2022 · 3 comments
Open

Auxiliary module of CVE-2019-18818 #16168

WackyHacker opened this issue Feb 10, 2022 · 3 comments
Labels
suggestion-module New module suggestions

Comments

@WackyHacker
Copy link

Summary

This exploit module abuses mishandling of password reset in JSON for Strapi CMS version 3.0.0-beta.17.4 to change the password of a privileged user.

Basic example

POC: https://wackyhacker.github.io/vulnearabilities/CVE-2019-18818/
Exploit-db: https://www.exploit-db.com/exploits/50716

Motivation

This module was created for industry professionals and pentesters to test the security of their web applications and determine whether to upgrade to a newer version in order to fix the flaw. It supports any web application that uses Strapi CMS and is expected to perform a password reset on a privileged user.

@WackyHacker WackyHacker added the suggestion-module New module suggestions label Feb 10, 2022
@smcintyre-r7
Copy link
Contributor

You could submit the module as a PR and we can see about accepting it since it looks like you already wrote it. We'd just be missing docs and it looks like the module might need a couple of changes.

@h00die
Copy link
Contributor

h00die commented Oct 1, 2022

If you provide instructions on getting this version to run in docker, i'll work on making the module framework compliant

@h00die h00die self-assigned this Oct 1, 2022
@h00die
Copy link
Contributor

h00die commented Oct 1, 2022

sorry, @WackyHacker on that last comment.

@h00die h00die removed their assignment Nov 27, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
suggestion-module New module suggestions
Projects
None yet
Development

No branches or pull requests

3 participants