CVE-2024-22107
HIGHGTB Central Console 15.17.1-30814.NG - Command Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-22107. PoCs published by X-C3LL.
AI-analyzed exploit summary The repository contains a functional exploit for CVE-2024-22107, targeting GTB Central Console v15.17.1-30814.NG. The exploit chains a pre-auth SQL injection to reset the Administrator password and a command injection to upload a webshell.
Description
An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method systemSettingsDnsDataAction at /opt/webapp/src/AppBundle/Controller/React/SystemSettingsController.php is vulnerable to command injection via the /old/react/v1/api/system/dns/data endpoint. An authenticated attacker can abuse it to inject an arbitrary command and compromise the platform.
Exploits (1)
The repository contains a functional exploit for CVE-2024-22107, targeting GTB Central Console v15.17.1-30814.NG. The exploit chains a pre-auth SQL injection to reset the Administrator password and a command injection to upload a webshell.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H