Atlassian Crowd pdkinstall Remote Code Execution
Posted by deepcore on August 13, 2021 – 8:26 am
This Metasploit module can be used to upload a plugin on Atlassian Cloud via the pdkinstall development plugin as an unauthenticated attacker. The payload is uploaded as a JAR archive containing a servlet using a POST request to /crowd/admin/uploadplugin.action. The check command will check that the /crowd/admin/uploadplugin.action page exists and that it responds appropriately to determine if the target is vulnerable or not.
Post a reply
You must be logged in to post a comment.