
Exploit CVE-2022-46364 in Apache CXF 3.2.14 for LFI and SSRF via MTOM/XOP injection. Automated multipart construction and Base64 extraction for HTB CTF environments.
This specialized exploit targets the DevArea environment on Hack The Box. It leverages a critical vulnerability in Apache CXF 3.2.14 (CVE-2022-46364) to perform Local File Inclusion (LFI) and Server-Side Request Forgery (SSRF).
The script abuses the MTOM/XOP (Message Transmission Optimization Mechanism) processing engine. By injecting an <xop:Include> element, we force the server's AttachmentDeserializer to fetch local system files or internal network resources and reflect them back in the SOAP response.
multipart/related structure required to trigger XOP processing.file:/// for local files and http:// for internal service scanning.<return> tag and decodes the Base64 content into readable text.requests library (pip install requests)python3 exploit.py -u http://machinename.htb:8080/employeeservice -r /etc/passwd
python3 exploit.py -u http://machinename.htb:8080/employeeservice -r http://127.0.0.1:8080/api
-u, --url: Target SOAP endpoint (usually http://devarea.htb:8080/employeeservice).-r, --resource: Target Resource: Absolute local path for LFI (e.g., /etc/passwd) or internal service URL for SSRF (e.g., http://127.0.0.1:8888/api).boundary and Content-Type: multipart/related.content field contains an XOP pointer to the desired file.<return> tag.This tool is intended for use in Hack The Box CTF environments and authorized security testing only.