
Exploit for CVE-2024-48322 targeting RunCodes instances. Retrieves user passwords via email inbox after authentication bypass, requiring only any valid account.
You need to have an account in the RunCodes instance, any privilege. Install with poetry and run providing the base url of the instance.
$ python pay.py <...>
Look at your email inbox, the password should be there.