Skip to content

Instantly share code, notes, and snippets.

View T0NG-J's full-sized avatar
💻
Still enumerating...

Tonggy T0NG-J

💻
Still enumerating...
View GitHub Profile
@T0NG-J
T0NG-J / CVE-2023-41892-POC.md
Created February 22, 2024 15:08 — forked from to016/CVE-2023-41892-POC.md
CVE-2023-41892 (Craft CMS Remote Code Execution) - POC [HTB] Surveillance

This Gist provides a Proof-of-Concept (POC) for CVE-2023-41892, a Craft CMS vulnerability that allows Remote Code Execution (RCE).

Overview

CVE-2023-41892 is a security vulnerability discovered in Craft CMS, a popular content management system. Craft CMS versions affected by this vulnerability allow attackers to execute arbitrary code remotely, potentially compromising the security and integrity of the application.

POC

This POC is depending on writing webshell, so finding a suitable folder with writable permission is necessary.