vendor:
Metadefender Core
by:
Ulascan Yildirim
9.8
CVSS
CRITICAL
Privilege Escalation
269
CWE
Product Name: Metadefender Core
Affected Version From: Metadefender Core 4.21.1
Affected Version To: Metadefender Core 4.21.1
Patch Exists: YES
Related CWE: CVE-2022-32272
CPE: a:opswat:metadefender_core:4.21.1
Platforms Tested: Windows / Linux
2022
OPSWAT Metadefender Core – Privilege Escalation
This is a PoC for the Metadefender Core Privilege escalation vulnerability. To use this PoC, you need a Username & Password. The OMS_CSRF_TOKEN allows users to execute commands with higher privileges.
Mitigation:
Ensure that users are not able to access the OMS_CSRF_TOKEN and session cookie.