/SonLogger-vulns

SonLogger Vulns (CVE-2021-27963, CVE-2021-27964)

Primary LanguageRuby

CVE-2021-27964 | SonLogger - Unauthenticated Arbitrary File Upload (Metasploit)

This module exploits an unauthenticated arbitrary file upload via insecure POST request. It has been tested on version 4.2.3.3 in Windows 10 Enterprise.

POC:

asciicast


CVE-2021-27963 | SonLogger - Insecure SuperAdmin Creation (Python)

This module exploit creates user with superadmin profile and shows some information about the application via insecure POST request. It has been tested on version 4.2.3.3 in Windows 10 Enterprise.

POC:

asciicast