
Proof-of-concept exploit for CVE-2024-53522, demonstrating decryption of HOSxP XE database credentials using a static hard-coded private key-IV.
Exploit PoC for CVE-2024-53522

This repository contains the Proof of Concept (PoC) for CVE-2024-53522, a vulnerability discovered by Safecloud Co., Ltd. For detailed information about the vulnerability, please refer to our blog post: CVE-2024-53522: HOSxP Software 0day Discover & Exploitation
CVE-2024-53522 is a critical security issue affecting HOSxP XE https://hosxp.net/. This vulnerability allows a local attacker to decrypt the credentials of the priviledge database credential due to the use of static hard-coded private key-IV in the application.
This PoC is provided for educational and research purposes only. Use of this PoC against unauthorized systems is strictly prohibited and may violate laws or agreements. The authors are not responsible for misuse or damages.