CVE-2024-38288: TurboMeeting – Post-Authentication Command Injection

CVE-2024-38288: TurboMeeting - Post-Authentication Command Injection-渗透云记 - 专注于网络安全与技术分享
CVE-2024-38288: TurboMeeting – Post-Authentication Command Injection
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2024-38288: TurboMeeting – Post-Authentication Command Injection

漏洞描述

The Certificate Signing Request (CSR) feature in the admin portal of the application is vulnerable to command injection. This vulnerability could allow authenticated admin users to execute arbitrary commands on the underlying server by injecting malicious input into the CSR generation process. The application failed to properly sanitize user-supplied input before using it in a command executed privileges.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享