Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-46164 PoC — Account takeover via prototype vulnerability

Source
Associated Vulnerability
Title:Account takeover via prototype vulnerability (CVE-2022-46164)
Description:NodeBB is an open source Node.js based forum software. Due to a plain object with a prototype being used in socket.io message handling a specially crafted payload can be used to impersonate other users and takeover accounts. This vulnerability has been patched in version 2.6.1. Users are advised to upgrade. Users unable to upgrade may cherry-pick commit `48d143921753914da45926cca6370a92ed0c46b8` into their codebase to patch the exploit.
Description
Basic POC exploit for CVE-2022-46164
Readme
# CVE-2022-46164-poc
Basic POC exploit for CVE-2022-46164
File Snapshot

[4.0K] /data/pocs/36a2ba0302c472382ee02fe10d0c3bde230f30d8 ├── [1.3K] LICENSE ├── [7.1K] poc.py └── [ 58] README.md 0 directories, 3 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →