id: aem-wcm-suggestions-servlet info: name: AEM WCM Suggestions Servlet author: DhiyaneshDk severity: low description: AEM WCM Suggestions Servlet is exposed. reference: - https://speakerdeck.com/0ang3el/hunting-for-security-bugs-in-aem-webapps?slide=96 metadata: max-request: 1 shodan-query: http.component:"Adobe Experience Manager" tags: aem,misconfig,intrusive http: - method: GET path: - '{{BaseURL}}/bin/wcm/contentfinder/connector/suggestions.json;%0aOJh.css?query_term=path%3a/&pre={{randstr}}' matchers-condition: and matchers: - type: status status: - 200 - type: word words: - '{{randstr}}' - '"results":' - '"suggestions":' condition: and # digest: 490a00463044022057cfdf96c2360217fdef716f23d44f208415611c12cc509b078327fa8fd6eafc022062069ce4d816e90e94403d2c31c5f49b92079f7526fa17b50b990b7a770a513e:922c64590222798bb761d5b6d8e72950