.. / CVE-2022-31854

Exploit for Codoforum 5.1 - Arbitrary File Upload (CVE-2022-31854)

Description:

Codoforum 5.1 contains an arbitrary file upload vulnerability via the logo change option in the admin panel. An attacker can upload arbitrary files to the server, which in turn can be used to make the application execute file content as code. As a result, an attacker can potentially obtain sensitive information, modify data, and/or execute unauthorized operations.

Nuclei Template

View the template here CVE-2022-31854.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2022/CVE-2022-31854.yaml
Copy

References:

https://vikaran101.medium.com/codoforum-v5-1-authenticated-rce-my-first-cve-f49e19b8bc
https://nvd.nist.gov/vuln/detail/CVE-2022-31854
https://codoforum.com
https://bitbucket.org/evnix/codoforum_downloads/downloads/codoforum.v.5.1.zip
https://github.com/trhacknon/Pocingit