vendor:
OpenFiler
by:
just a nonroot user
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: OpenFiler
Affected Version From: OpenFiler 2.3
Affected Version To: OpenFiler 2.3
Patch Exists: NO
Related CWE: N/A
CPE: a:openfiler:openfiler
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Exploit code (PoC) for OpenFiler 2.3 (current)
This exploit code allows a non-root user to bypass authentication and gain access to the OpenFiler 2.3 system. The code takes the host URL, a username and password as input and then uses a fake password to bypass authentication. If the exploit is successful, the user can login with the provided username and password.
Mitigation:
Ensure that authentication is properly implemented and that all users are required to provide valid credentials before being granted access.