Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Hack-The-Box-Nexus-Findings-Report — HTB_Nexus Penetration Test Report – Comprehensive security assessment documenting credential leakage from Gitea, CVE-2026-38526 exploitation in Krayin CRM, and privilege escalation via Gitea template sync directory traversal. Mapped to MITRE ATT&CK and NSA D3FEND frameworks with actionable remediation roadmap and full evidence appendix. | Kitploit
Tools/GitHubGitHub/mmoobbeeiidat-design/hack-the-box-nexus-findings-report
Privilege EscalationReconnaissanceVulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringCTFPenetration TestingLearning & Education

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

About

HTB_Nexus Penetration Test Report – Comprehensive security assessment documenting credential leakage from Gitea, CVE-2026-38526 exploitation in Krayin CRM, and privilege escalation via Gitea template sync directory traversal. Mapped to MITRE ATT&CK and NSA D3FEND frameworks with actionable remediation roadmap and full evidence appendix.

GitHubmmoobbeeiidat-design/hack-the-box-nexus-findings-report

Hack-The-Box-Nexus-Findings-Report

View RepositoryWebsite
22 months agoNot yet reviewed
Share

🛡️ Hack The Box - Nexus Findings Report

📋 Overview

This repository contains a comprehensive penetration test report for the Hack The Box machine Nexus.

🔍 Key Findings

  • Exposed Credentials in Gitea Commit History - Medium Severity
  • Krayin CRM Unrestricted File Upload (CVE-2026-38526) - High Severity
  • Gitea Template Sync Directory Traversal - Critical Severity
  • User flag captured: 3290dde5fca195ea451632d54d4b60da
  • Root flag captured: c25914b5b518500d1c71da5c8331ac9d

🛠️ Frameworks Used

  • PentNote - Automated documentation - https://github.com/A1GCH-afk/PentNote
  • MITRE ATT&CK - T1190, T1552.004, T1078.003, T1548.001
  • NSA D3FEND - D3-FUAC, D3-APIT, D3-CWAM

📄 Full Report

View the complete report: Nexus.md

Download Tool