
Strapi Framework にリモートコード実行の脆弱性
Strapiフレームワークはリモートコード実行に対して脆弱です
まあ、CVE-2019-19609用のエクスプロイトは見つからなかったので、自分で書きました。:/
python3 exploit.py <rhost> <lhost> <jwt> <url>
https://hack-fast.herokuapp.com/cve/CVE-2019-19609
https://github.com/strapi/strapi/pull/4636