module
WSO2 Arbitrary File Upload to RCE
| Disclosed | Created |
|---|---|
| Apr 1, 2022 | Apr 29, 2022 |
Disclosed
Apr 1, 2022
Created
Apr 29, 2022
Description
This module abuses a vulnerability in certain WSO2 products that allow unrestricted file
upload with resultant remote code execution. This affects WSO2 API Manager 2.2.0 and
above through 4.0.0; WSO2 Identity Server 5.2.0 and above through 5.11.0; WSO2 Identity Server
Analytics 5.4.0, 5.4.1, 5.5.0, and 5.6.0; WSO2 Identity Server as Key Manager 5.3.0 and above
through 5.10.0; and WSO2 Enterprise Integrator 6.2.0 and above through 6.6.0.
upload with resultant remote code execution. This affects WSO2 API Manager 2.2.0 and
above through 4.0.0; WSO2 Identity Server 5.2.0 and above through 5.11.0; WSO2 Identity Server
Analytics 5.4.0, 5.4.1, 5.5.0, and 5.6.0; WSO2 Identity Server as Key Manager 5.3.0 and above
through 5.10.0; and WSO2 Enterprise Integrator 6.2.0 and above through 6.6.0.
Authors
Platform
Java
Architectures
java
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.