
CVE-2024-51567 is a Python PoC exploit targeting an RCE vulnerability in CyberPanel v2.3.6’s upgrademysqlstatus endpoint, bypassing CSRF protections.
CVE-2024-51567 is a Python proof-of-concept (PoC) exploit script for CVE-2024-51567, a critical command injection vulnerability affecting CyberPanel v2.3.6. This vulnerability, found in the upgrademysqlstatus endpoint, enables remote command execution (RCE) by bypassing CSRF protections and utilizing shell metacharacters in specific parameters.
⚠️ Important Disclaimer: This script is intended for educational purposes and authorized security testing on systems you own or have explicit permission to test. Unauthorized use of this script on any system is illegal and punishable by law. The author assumes no responsibility for misuse. Always adhere to ethical standards and applicable laws.
upgrademysqlstatus endpoint in databases/views.py of CyberPanel (prior to commit 5b08cd6) allows remote attackers to execute arbitrary commands by bypassing secMiddleware protections, which only filter POST requests. This vulnerability can be exploited using shell metacharacters in the statusfile parameter./dataBases/upgrademysqlstatus endpointhttpx modulegit clone https://github.com/ajayalf/CVE-2024-51567.git
cd CVE-2024-51567
httpx is installed:
pip install httpx
To run the script on a single target, use the following command:
python CVE-2024-51567.py <target-url>
Example:
python CVE-2024-51567.py http://example.com
To run the script on multiple targets, create a text file with a list of target URLs (one URL per line), and use the command:
python CVE-2024-51567.py <targets.txt>
Example:
python CVE-2024-51567.py targets.txt
If you want to use multiple targets, create a text file named targets.txt or any preferred name. The format of the file should be a list of URLs, with one URL per line, as shown below:
http://target1.com
http://target2.com
http://target3.com
After the script connects to a target, you can enter shell commands to execute on the target server. To exit, type exit or quit.
get_CSRF_token(client): Retrieves the CSRF token from cookies on the target's main page.
client (an httpx.Client object)pwn(client, CSRF_token, cmd): Sends a crafted payload with the CSRF token and the desired command.
client (an httpx.Client object), CSRF_token (string), cmd (string)exploit(client, cmd): Executes the pwn function on the target to run the command and prints the output.
client (an httpx.Client object), cmd (string)run_exploit(target): Initializes a connection to the target and starts an interactive command loop.
target (string, target URL)exit or quit.Main Execution: Checks the argument to determine if the target is a single URL or a file with multiple targets.
If the CSRF token is not found in the cookies, the script will print all received cookies and exit with a helpful error message.
/ is the correct endpoint for obtaining the CSRF token. If it is different, modify the function get_CSRF_token accordingly.For further information regarding this vulnerability, please refer to the following resources: