Monitorr 1.7.6m / 1.7.7d Remote Code Execution
Posted by deepcore on March 24, 2023 – 11:24 am
This Metasploit module exploits an arbitrary file upload vulnerability and achieves remote code execution in the Monitorr application. Using a specially crafted request, custom PHP code can be uploaded and injected through endpoint upload.php because of missing input validation. Any user privileges can exploit this vulnerability and it results in access to the underlying operating system with the same privileges under which the web services run (typically user www-data). Monitorr versions 1.7.6m, 1.7.7d, and below are affected.
Post a reply
You must be logged in to post a comment.