Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/noname-elv/cve-2026-48907
Vulnerability AnalysisExploitationScripting & AutomationWeb Application ExploitationPost-ExploitationWeb SecurityPenetration TestingRemote Access ToolPayload Development
GitHubnoname-elv/cve-2026-48907

CVE-2026-48907

Python CLI that exploits CVE-2026-48907 in Joomla JCE via profile-import upload, verifies shell paths, and opens an interactive command channel on authorized targets.

View Repository
12320 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

E.L.V CVE Research & Assessment Framework

E.L.V — Exploit Loader & Vulnerability Firmware
Cybersecurity research utility for authorized vulnerability assessment.

Python Platform License


Table of Contents

  • Overview
  • Important Safety Notice
  • Project Information
  • What the Current Script Does
  • Workflow
  • Requirements
  • Installation
  • Command-Line Interface
  • Input Files
  • Output
  • Concurrency
  • Network Behavior
  • SSL/TLS Behavior
  • Logging and Results
  • Error Handling
  • Source Code Structure
  • Security Considerations
  • Responsible Testing Methodology
  • Troubleshooting
  • Development Notes
  • Known Limitations
  • Future Improvements
  • License
  • Disclaimer

Overview

E.L.V CVE Research & Assessment Framework is a Python-based command-line utility intended for controlled security research and authorized vulnerability assessment.

The supplied implementation contains functionality for:

  • accepting a single target or a target-list file;
  • loading a locally supplied payload file;
  • performing an HTTP-based pre-check;
  • extracting a CSRF-related token from a target response;
  • submitting a profile-import request;
  • checking a set of candidate paths for the uploaded file;
  • optionally opening an interactive HTTP command channel when a single target is used;
  • processing multiple targets concurrently;
  • writing successful shell URLs to a result file.

The current source identifies its research target as:

CVE-2026-48907 Joomla! JCE Extension < 2.9.99.5 Unauthenticated RCE

That CVE/product claim is metadata supplied by the source code and has not been independently verified by this README. Before publishing a security claim, validate the identifier, affected versions, advisory, affected component, and remediation information against a trusted vendor/CVE source.


Important Safety Notice

This project interacts with remote web applications and the supplied implementation includes functionality intended to upload a custom server-side payload and communicate with an uploaded shell.

Use it only against systems for which you have explicit authorization.

Do not use this project to:

  • access systems without permission;
  • deploy a shell to third-party infrastructure;
  • obtain unauthorized persistence;
  • bypass authentication or access controls;
  • execute commands on systems you do not own or have written authorization to test;
  • scan arbitrary Internet targets without authorization;
  • damage, modify, exfiltrate, or destroy data.

For a safe laboratory, use an isolated local VM/container environment or a deliberately vulnerable training target.


Project Information

FieldValue
ProjectE.L.V CVE Research & Assessment Framework
Author / EngineHxN / E.L.V
Version1.0.0
LanguagePython
Platform*nix / Unix-like systems
LicenseGNU GPL v3
InterfaceCommand line
HTTP Clientrequests
ConcurrencyThreadPoolExecutor
Primary PurposeAuthorized security research and assessment

What the Current Script Does

The supplied elv-cve.py source contains the following major components.

1. Custom payload loading

The script reads a local file supplied through the --shell option.

The source describes this as a custom shell/uploader file and terminates when the specified file cannot be read.

2. Target discovery

The program supports two mutually exclusive target modes:

  • one target URL;
  • a text file containing multiple target URLs.

3. Initial HTTP request

For each target, the script performs a GET request against the target root and expects an HTTP 200 response before continuing.

4. Token extraction

The implementation searches the returned HTML for a CSRF-related value using regular expressions.

Two patterns are currently implemented.

5. Profile import request

The script constructs a multipart upload request against:

/index.php?option=com_jce

The request includes the profile-import task and the extracted token.

6. Candidate-path verification

After the upload request, the program checks several possible locations for the resulting file.

The current source contains these candidate paths:

/tmp/
 /images/
 /images/stories/
 /media/

7. Interactive session

For a single target, the current program invokes an interactive command interface when it reports a successful uploaded shell path.

The source sends commands using POST parameters named:

cmd
c

Because this functionality can result in remote command execution, it should be restricted to isolated, explicitly authorized environments.

8. Multi-target processing

When a target file is supplied, the program uses a ThreadPoolExecutor and processes targets concurrently.

The default thread count in the source is:

10

Workflow

At a high level, the current implementation follows this flow:

Start
  │
  ├── Parse command-line arguments
  │
  ├── Load local payload file
  │
  ├── Load one target OR target list
  │
  ├── Create ELV_CVE output directory
  │
  ├── Target processing
  │     │
  │     ├── GET target
  │     ├── Check HTTP response
  │     ├── Extract token
  │     ├── Submit profile-import request
  │     ├── Check candidate file paths
  │     └── Record result
  │
  └── Write results / display summary

Requirements

The supplied source imports:

  • Python standard-library modules:
    • random
    • re
    • time
    • argparse
    • sys
    • os
    • json
    • threading
    • concurrent.futures
  • third-party modules:
    • requests
    • urllib3

A minimal dependency installation is therefore:

python3 -m pip install requests urllib3

For reproducible deployments, pin dependencies in a requirements.txt file.

Example:

requests
urllib3

Installation

Clone or copy the project into an isolated assessment environment.

Example:

git clone <YOUR-REPOSITORY-URL>
cd <YOUR-REPOSITORY-DIRECTORY>

Create a virtual environment:

python3 -m venv .venv

Activate it:

source .venv/bin/activate

Install dependencies:

python3 -m pip install -r requirements.txt

Verify Python:

python3 --version

Verify the dependency:

python3 -c "import requests, urllib3; print('Dependencies OK')"

Replace <YOUR-REPOSITORY-URL> and <YOUR-REPOSITORY-DIRECTORY> with the values used by your repository.


Command-Line Interface

The source defines the following command-line options.

Target selection

-u, --url

Single target URL.

-f, --file

Path to a file containing target URLs.

These options are mutually exclusive and one of them is required.

Payload selection

--shell

Path to the local custom payload file.

This argument is required by the current implementation.

Thread count

-t, --threads

Number of worker threads.

Default:

10

Verbose flag

-v, --verbose

Enables the verbose flag exposed by the argument parser.

Download Tool