b3gund4L icon

Laravel Media Library Pro 2.1.6 Shell Upload Vulnerability

b3gund4L | PRO | 07/21/22 04:02:24 PM UTC | 0 ⭐ | 4036 👁️ | Never ⏰ | []
PHP |

1.25 KB

|

None

|

0 👍

/

0 👎

# Exploit Title: Laravel Media Library Pro <=2.1.6 - Arbitrary File Upload (Unauthenticated)  
# Exploit Author: Kelvin Yip <[email protected]>
# Vendor Homepage: https://spatie.be/ 
# Software Link: https://spatie.be/products/media-library-pro
# Version: <=1.17.10 & <=2.1.6
# Tested on: Laradock (PHP 8.0) inside Ubuntu 20.04
# CVE : CVE-2021-45040
 
#######################################################################################################
Description:
 
The Spatie media-library-pro library through 1.17.10 & 2.1.6 for Laravel allows remote attackers to upload executable files via the uploads route.
 
#######################################################################################################
Xploit : Arbitrary File Upload (Unauthenticated)
 
Default URL: http://server/api/media-library-pro/uploads OR http://server/media-library-pro/uploads
 
Note: The URL can be changed by developer. 
 
Upload a PHP webshell or shell file with 3 parameters: (uuid, name and file), the JSON response will contain “original_url”, access the URL in the browser to get the shell access.
 
#######################################################################################################
 
#  0day.today [2022-07-21]  #

Comments

  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  • Quinwatir icon
    03/29/26 11:03:44 PM UTC
    CSS |

    0 B

    |

    0 👍

    /

    0 👎

    ✅ Leaked Exploit Documentation:
     
    https://docs.google.com/document/d/1dOCZEHS5JtM51RITOJzbS4o3hZ-__wTTRXQkV1MexNQ/edit?usp=sharing
     
    This made me $13,000 in 2 days.
     
    Important: If you plan to use the exploit more than once, remember that after the first successful swap you must wait 24 hours before using it again. Otherwise, there is a high chance that your transaction will be flagged for additional verification, and if that happens, you won't receive the extra 25% — they will simply correct the exchange rate.
    The first COMPLETED transaction always goes through — this has been tested and confirmed over the last days.
     
    Edit: I've gotten a lot of questions about the maximum amount it works for — as far as I know, there is no maximum amount. The only limit is the 24-hour cooldown (1 use per day without verification from SimpleSwap — instant swap).
    
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎