cve/2021/CVE-2021-26551.md
2024-06-18 02:51:15 +02:00

827 B

CVE-2021-26551

Description

An issue was discovered in SmartFoxServer 2.17.0. An attacker can execute arbitrary Python code, and bypass the javashell.py protection mechanism, by creating /config/ConsoleModuleUnlock.txt and editing /config/admin/admintool.xml to enable the Console module.

POC

Reference

Github

No PoCs found on GitHub currently.