Description
This module exploits a server-side include (SSI) in SharePoint to leak the web.config file and forge a malicious ViewState with the extracted validation key.
This exploit is authenticated and requires a user with page creation privileges, which is a standard permission in SharePoint.
The web.config file will be stored in loot once retrieved, and the VALIDATION_KEY option can be set to short-circuit the SSI and trigger the ViewState deserialization.
Tested against SharePoint 2019 on Windows Server 2016.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/windows/http/sharepoint/ssi_viewstatemsf undefined(ssi_viewstate) > show actions ...actions...msf undefined(ssi_viewstate) > set ACTION < action-name >msf undefined(ssi_viewstate) > show options ...show and set options...msf undefined(ssi_viewstate) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub