漏洞描述
Detected Beszel server monitoring hub had an unfinished installation with no admin account configured, allowing attackers to create an admin account and gain full control.
id: beszel-unfinished-installation
info:
name: Beszel Unfinished Installation
author: 0x_Akoko
severity: high
description: |
Detected Beszel server monitoring hub had an unfinished installation with no admin account configured, allowing attackers to create an admin account and gain full control.
reference:
- https://github.com/henrygd/beszel
metadata:
verified: true
max-request: 1
shodan-query: html:"globalThis.BESZEL"
fofa-query: body="globalThis.BESZEL"
tags: beszel,misconfig,install,exposure
http:
- method: GET
path:
- "{{BaseURL}}/api/beszel/first-run"
matchers:
- type: dsl
dsl:
- 'status_code == 200'
- 'contains(content_type, "application/json")'
- 'contains(body, "\"firstRun\":true")'
condition: and
# digest: 4a0a00473045022100e616d9af72c4c1371be6ca0d5b7f078633da30df5b51253e6dfe88cf104ba4d90220070b11bae97afa2e95ecb89aaa0a8818a2aa8720636862f25d7c7005705cbdf7:922c64590222798bb761d5b6d8e72950