Exploitation Summary
EIP tracks 1 public exploit for CVE-2022-30286. PoCs published by Momen Eldawakhly.
AI-analyzed exploit summary This exploit leverages PyScript's ability to execute Python code in the browser to read local Python library files and exfiltrate console logs via a Burp Collaborator endpoint. It demonstrates an information leakage vulnerability by accessing restricted filesystem paths and sending data to an attacker-controlled server.
Description
pyscriptjs (aka PyScript Demonstrator) in PyScript through 2022-05-04 allows a remote user to read Python source code.
Exploits (1)
This exploit leverages PyScript's ability to execute Python code in the browser to read local Python library files and exfiltrate console logs via a Burp Collaborator endpoint. It demonstrates an information leakage vulnerability by accessing restricted filesystem paths and sending data to an attacker-controlled server.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N