CVE-2024-23738# CVE-2024-23738
An issue in Postman through 10.22 on macOS allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.
There is a tool designed to automate the process of searching for vulnerabilities in electron: https://github.com/r3ggi/electroniz3r
<img width="1277" alt="image" src="https://github.com/V3x0r/CVE-2024-23738/assets/83291215/19665649-67b9-4e48-90ea-af64a9fe7ed3">
With this tool, we can check if the App is Vulnerable:
<img width="710" alt="image" src="https://github.com/V3x0r/CVE-2024-23738/assets/83291215/d2465158-af23-478b-b975-25c1f2bc90ed">
After validation, we can inject our code, and get a shell
<img width="843" alt="image" src="https://github.com/V3x0r/CVE-2024-23738/assets/83291215/cd658b45-7fdd-4e12-bf75-61a8efb2ff85">
Enjoy Your Shell :)
登录后查看神龙缓存的 POC 文件快照
登录查看