
Exploit script for CVE-2022-29464, a preauth arbitrary file upload vulnerability in WSO2 products, enabling RCE via malicious JSP file upload.
A preauth arbitrary file upload that leads to RCE in WSO2
CVE-2022-29464 is a RCE vulnerability for WSO2 discovered by Orange Tsai. A unauthenticated arbitrary file upload allows an attacker to execute code by uploading a malicious JSP file.
Uploads a JSP shell