漏洞描述
ChurchCRM setup is exposed.
id: churchcrm-installer
info:
name: ChurchCRM - Setup Exposure
author: Kazgangap
severity: high
description: |
ChurchCRM setup is exposed.
reference:
- https://github.com/ChurchCRM/CRM
metadata:
vendor: churchcrm
product: churchcrm
shodan-query: http.title:"churchcrm"
fofa-query: app="churchcrm"
tags: misconfig,setup,churchcrm,exposure,vuln
http:
- method: GET
path:
- "{{BaseURL}}/setup"
host-redirects: true
max-redirects: 2
matchers:
- type: dsl
dsl:
- 'contains(body, "ChurchCRM setup wizard")'
- "status_code == 200"
condition: and
# digest: 4a0a00473045022100d459f75d3237e42a6310578921a93def258fb96fe65755fcfc1b943a2425538402207370e3bb3f3d4e899ede265e5070876d3ba24c0e6dfc17501d7b9764dcad9153:922c64590222798bb761d5b6d8e72950