漏洞描述 Appsmith 是一款开源的低代码开发平台,专注于帮助企业快速构建内部工具。在Appsmith 1.52 之前的版本中存在代码执行漏洞,攻击者可注册账户,并通过应用程序连接本地postgres执行任意命令获取服务器权限。
相关漏洞推荐 POC postgresql-cluster-config: PostgreSQL Cluster - Configuration POC postgresql-audit-disabled: PostgreSQL Database Instances - SQL Auditing Disabled POC azure-postgresql-db-delete-unalerted: Azure PostgreSQL Database Delete Alert Not Configured POC azure-postgresql-db-update-unalerted: Azure PostgreSQL Database Create/Update Alert Not Configured POC azure-nsg-postgresql-unrestricted: Unrestricted PostgreSQL Database Access in Azure NSGs POC azure-postgres-allow-azure-services-disabled: Azure PostgreSQL Access From Azure Services Disabled POC azure-postgres-connection-throttling-disabled: Azure PostgreSQL Server Connection Throttling Disabled POC azure-postgres-double-encryption-disabled: Azure PostgreSQL Single Server Double Encryption Not Enabled POC azure-postgres-log-checkpoints-disabled: Azure PostgreSQL Flexible Server log_checkpoints Disabled POC azure-postgres-log-connections-disabled: Azure PostgreSQL Log Connections Not Enabled POC azure-postgres-log-disconnections-disabled: Azure PostgreSQL Log Disconnections Not Enabled POC azure-postgres-log-duration-disabled: Azure PostgreSQL Log Duration Not Enabled POC azure-postgresql-geo-backup-disabled: Azure PostgreSQL Geo-Redundant Backup Not Enabled