Exploitation Summary
EIP tracks 1 public exploit for CVE-2022-36536.
PoCs published by Jan Rude, including Metasploit module auxiliary/scanner/http/syncovery_linux_token_cve_2022_36536.
AI-analyzed exploit summary This Metasploit module brute-forces Syncovery for Linux Web-GUI session tokens by generating all possible base64-encoded timestamps within a specified date range. It exploits CVE-2022-36536, where session tokens are derived from predictable timestamps instead of random values.
Description
An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below allows attackers to escalate privileges via creating crafted session tokens.
Exploits (1)
This Metasploit module brute-forces Syncovery for Linux Web-GUI session tokens by generating all possible base64-encoded timestamps within a specified date range. It exploits CVE-2022-36536, where session tokens are derived from predictable timestamps instead of random values.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H