Abbiamo fornito due file:-
- CVE-2023-38646-POC.py per verificare se una qualsiasi istanza Metabase sta perdendo il setup-token.
- CVE-2023-38646-Reverse-Shell.py per ottenere una reverse shell sulla macchina controllata dall'attaccante.
CVE-2023-38646-POC.py

CVE-2023-38646-Reverse-Shell.py

Come Usare
git clone https://github.com/securezeron/CVE-2023-38646
cd CVE-2023-38646
pip install -r requirements.txt
python3 CVE-2023-38646-Reverse-Shell.py -h