Description
This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator. This module uses the administrator account to install a malicious .jsp servlet plugin which the user can trigger to gain code execution on the target in the context of the of the user running the confluence server.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/multi/http/atlassian/confluence_unauth_backupmsf undefined(confluence_unauth_backup) > show actions ...actions...msf undefined(confluence_unauth_backup) > set ACTION < action-name >msf undefined(confluence_unauth_backup) > show options ...show and set options...msf undefined(confluence_unauth_backup) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub