Description
This module exploits a pre-auth remote code execution vulnerability in SmarterTools SmarterMail before version 100.0.9413. The endpoint /api/upload fails to sanitize the contextData POST parameter which can contain JSON data with a "guid" key that allows directory traversal. By leveraging this vulnerability, an unauthenticated attacker can upload a malicious ASPX web shell to the server's web root directory, leading to remote code execution.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/multi/http/smartermail/guid_file_uploadmsf undefined(guid_file_upload) > show actions ...actions...msf undefined(guid_file_upload) > set ACTION < action-name >msf undefined(guid_file_upload) > show options ...show and set options...msf undefined(guid_file_upload) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub