CVE-2024-45256
CRITICALBYOB Unauthenticated RCE via Arbitrary File Write and Command Injection (CVE-2024-45256, CVE-2024-45257)
Title source: metasploitExploitation Summary
EIP tracks 1 public exploit for CVE-2024-45256.
PoCs published by chebuya, Valentin Lobstein, including Metasploit module exploits/unix/webapp/byob_unauth_rce.
AI-analyzed exploit summary This Metasploit module exploits CVE-2024-45256 and CVE-2024-45257 in BYOB (Build Your Own Botnet) by chaining an unauthenticated arbitrary file write to modify the SQLite database and an authenticated command injection for RCE.
Description
An arbitrary file write issue in the exfiltration endpoint in BYOB (Build Your Own Botnet) 2.0 allows attackers to overwrite SQLite databases and bypass authentication via an unauthenticated HTTP request with a crafted parameter. This occurs in file_add in api/files/routes.py.
Exploits (1)
This Metasploit module exploits CVE-2024-45256 and CVE-2024-45257 in BYOB (Build Your Own Botnet) by chaining an unauthenticated arbitrary file write to modify the SQLite database and an authenticated command injection for RCE.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H