CVE-2024-30851
MEDIUMJasmin Ransomware Web Server Unauthenticated SQL Injection
Title source: metasploitExploitation Summary
EIP tracks 3 public exploits for CVE-2024-30851.
PoCs published by chebuya, chebuya, h00die, including Metasploit module auxiliary/gather/jasmin_ransomware_sqli.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2024-30851, demonstrating a path traversal vulnerability in the Jasmin Ransomware web panel. The exploit leverages an authentication bypass via SQL injection and unsanitized file read operations to dump decryption keys and arbitrary files.
Description
Directory Traversal vulnerability in codesiddhant Jasmin Ransomware v.1.0.1 allows an attacker to obtain sensitive information via the download_file.php component.
Exploits (3)
This repository contains a functional exploit for CVE-2024-30851, demonstrating a path traversal vulnerability in the Jasmin Ransomware web panel. The exploit leverages an authentication bypass via SQL injection and unsanitized file read operations to dump decryption keys and arbitrary files.
This Metasploit module exploits an unauthenticated SQL injection vulnerability in the Jasmin Ransomware web server's login functionality. It uses time-based blind SQLi to dump credentials and victim data from the database.
This Metasploit module exploits an unauthenticated directory traversal vulnerability in the Jasmin Ransomware web server via the 'download_file.php' endpoint. It allows arbitrary file retrieval by manipulating the 'file' parameter with traversal sequences.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N