Headline
CVE-2021-44103: KONGA 0.14.9 - Privilege Escalation (Exploit)
Vertical Privilege Escalation in KONGA 0.14.9 allows attackers to higher privilege users to full administration access. The attack vector is a crafted condition, as demonstrated by the /api/user/{ID} at ADMIN parameter.
terça-feira, 16 de novembro de 2021
KONGA 0.14.9 - Privilege Escalation (Exploit)
Report Vulnerability
Product: KONGA Model: 0.14.9 Vulnerability: Privilege EscalationImpact: Full admin access (v__ertical privilege escalation)****Authentication: required ****Exploit Author: Fabricio Salomao (@_SOl0m0n) / Paulo Trindade (@paulotrindadec)
PoC
Bellow has created a normal user called “usernormal” without privilege.
Through of request bellow was changed the flag “FALSE” in the parameter “admin” to "TRUE".
After running the exploit, the privilege escalation was a success!
Result:
Nenhum comentário:
Postar um comentário