Exploitation Summary
EIP tracks 1 public exploit for CVE-2023-36348. PoCs published by yuyudhn.
AI-analyzed exploit summary This exploit demonstrates an authenticated file upload vulnerability in POS Codekop v2.0, allowing an attacker to upload a malicious PHP file disguised as an image, leading to Remote Code Execution (RCE). The PoC includes a Burp request showing the upload of a PHP web shell with a JFIF header to bypass content-type checks.
Description
POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename parameter.
Exploits (1)
This exploit demonstrates an authenticated file upload vulnerability in POS Codekop v2.0, allowing an attacker to upload a malicious PHP file disguised as an image, leading to Remote Code Execution (RCE). The PoC includes a Burp request showing the upload of a PHP web shell with a JFIF header to bypass content-type checks.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H