3cx-config: 3CX Config - File Disclosure

日期: 2025-08-01 | 影响软件: 3CX Config | POC: 已公开

漏洞描述

3CX Configuration file was discovered.

PoC代码[已公开]

id: 3cx-config

info:
  name: 3CX Config - File Disclosure
  author: DhiyaneshDk
  severity: low
  description: |
    3CX Configuration file was discovered.
  reference:
    - https://www.3cx.com/docs/configure-pbx-automatically/
  metadata:
    verified: true
    max-request: 1
    shodan-query: html:"setupconfig.xml"
  tags: 3cx,config,exposure,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/SetupConfig.xml"

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - "3CX"
          - "<SetupConfig"
        condition: and

      - type: word
        part: content_type
        words:
          - "application/xml"
# digest: 4b0a0048304602210097627565721836af3f6ed0604df87a780f4387604adda5c93418f73dbbf0c7a302210082344219749f00a3a247aaf43b2910ed3ba8195771d3b154b27b63690cb793cd:922c64590222798bb761d5b6d8e72950