Exploitation Summary
EIP tracks 1 public exploit for CVE-2022-31245. PoCs published by ly1g3.
AI-analyzed exploit summary This repository contains a working proof-of-concept exploit for CVE-2022-31245, a command injection vulnerability in Mailcow's Sync Job feature. The exploit allows an authenticated user to execute arbitrary commands via the 'Custom Parameters' field, bypassing a case-sensitive check, and includes a Python script to automate the attack.
Description
mailcow before 2022-05d allows a remote authenticated user to inject OS commands and escalate privileges to domain admin via the --debug option in conjunction with the ---PIPEMESS option in Sync Jobs.
Exploits (1)
This repository contains a working proof-of-concept exploit for CVE-2022-31245, a command injection vulnerability in Mailcow's Sync Job feature. The exploit allows an authenticated user to execute arbitrary commands via the 'Custom Parameters' field, bypassing a case-sensitive check, and includes a Python script to automate the attack.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H