Exploits / Vulnerability Discovered : 2021-01-12 |
Type : webapps |
Platform : multiple
This exploit / vulnerability Smartagent 3.1.0 privilege escalation is for educational purposes only and if it is used you will do on your own risk!
[+] Code ...
# Exploit Title: SmartAgent 3.1.0 - Privilege Escalation
# Date: 01-11-2021
# Exploit Author: Orion Hridoy
# Vendor Homepage: https://www.smartagent.io/
# Version: Build 3.1.0
# Tested on: Windows 10/Kali Linux
A Low grade user like ViewOnly can create an account with SuperUser
permission.
Steps To Reproduce:
1. Create a user with ViewOnly
2. Visit https://demo.localhost.com/#/CampaignManager/users
3. Now you will be able to create an account with SuperUser.
#Python Exploit [Replace With Your Authorization Code]