Exploitation Summary
EIP tracks 1 public exploit for CVE-2025-0364. PoCs published by vulncheck-oss.
AI-analyzed exploit summary This repository contains a Go-based exploit for CVE-2025-0364, which targets BigAntSoft BigAnt Server. The exploit bypasses authentication via SaaS account registration and uploads a malicious PHP file to achieve unauthenticated remote code execution.
Description
BigAntSoft BigAnt Server, up to and including version 5.6.06, is vulnerable to unauthenticated remote code execution via account registration. An unauthenticated remote attacker can create an administrative user through the default exposed SaaS registration mechanism. Once an administrator, the attacker can upload and execute arbitrary PHP code using the "Cloud Storage Addin," leading to unauthenticated code execution.
Exploits (1)
This repository contains a Go-based exploit for CVE-2025-0364, which targets BigAntSoft BigAnt Server. The exploit bypasses authentication via SaaS account registration and uploads a malicious PHP file to achieve unauthenticated remote code execution.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H