
Go-based proof-of-concept exploit for CVE-2022-23131, a Zabbix SAML authentication bypass. Enables unauthorized admin access by forging SAML assertions. Includes a check command for target validation.
cve-2022-23131
This program is only for internal risk self-inspection by client enterprise users, and is prohibited for any form of unauthorized security testing.
fofa: app="ZABBIX-监控系统" && body="saml"
Usage:
go build -o zexp
chmod a+x zexp
./zexp check -t https://x.x.x.x/index.php -u Admin
Screenshots:

