CVE HUB 👾
787 subscribers
19.3K links
Github Red team resource push
Github 红队资源推送
Cve/Rce/Exploit/Redteam/漏洞利用/红队

Channel push 24/7 (real time)
频道全天候推送(实时)
Download Telegram
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-31007
Github: https://github.com/gscharf/CVE-2022-31007-Python-POC
Describe:
eLabFTW is an electronic lab notebook manager for research teams. Prior to version 4.3.0, a vulnerability allows an authenticated user with an administrator role in a team to assign itself system administrator privileges within the application, or create a new system administrator account. The issue has been corrected in eLabFTW version 4.3.0. In the context of eLabFTW, an administrator is a user account with certain privileges to manage users and content in their assigned team/teams. A system administrator account can manage all accounts, teams and edit system-wide settings within the application. The impact is not deemed as high, as it requires the attacker to have access to an administrator account. Regular user accounts cannot exploit this to gain admin rights. A workaround for one if the issues is removing the ability of administrators to create accounts.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-26265
Github: https://github.com/Inplex-sys/CVE-2022-26265
Describe:
Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.
👾KEYWORD SERVICE 🏷#免杀
Name: powershell-obfuscation
Github: https://github.com/H4de5-7/powershell-obfuscation