Preparing to download the repository
- Update packages:
sudo apt update
- If necessary, install git:
sudo apt install -y git
- It is necessary to set up port forwarding rules. In the "Network" settings of the Debian 12.11.0 machine, click "Port Forwarding".
- Add a rule:
Name: Django;
Protocol: TCP;
Host Address: empty;
Host Port: 8000;
Host Address: empty;
Guest Port: 8000.
Downloading the repository, installing the vulnerable web application
- Download the repository:
git clone https://github.com/alxsourin/Helpdesk-Telecom-CVE-2025-64459.git
- Navigate to the directory:
cd Helpdesk-Telecom-CVE-2025-64459
- Run the installation and setup of the web application:
./setup.sh
Launching the web application
- Activate the Python virtual environment:
source venv/bin/activate
- Launch the web application:
python manage.py runserver 0.0.0.0:8000
- The web application will be available at: http://localhost:8000/
The exploitation of CVE-2025-64459 in the web application is presented in the .pdf file