GobyVuls/Chemex/CNVD-2021-15573
2021-09-24 17:55:11 +08:00
..
2021-09-24 17:54:47 +08:00

Chemex Auth File Upload CNVD-2021-15573

Coffee pot Chemex is a free, open source, efficient and beautiful IT operation and maintenance management platform. Chemex has a background file upload vulnerability(default login admin:admin), which can be exploited by attackers to gain control of the server.

FOFA query rule: (title="咖啡壶" || body="让IT资产管理更加简单") && body="CreateDcat"

Demo

Chemex_Auth_File_Upload_CNVD_2021_15573