connectwise-setup: ConnectWise Setup Wizard - Exposure

日期: 2025-08-01 | 影响软件: ConnectWise Setup Wizard | POC: 已公开

漏洞描述

PoC代码[已公开]

id: connectwise-setup

info:
  name: ConnectWise Setup Wizard - Exposure
  author: DhiyaneshDk
  severity: high
  classification:
    cpe: cpe:2.3:a:connectwise:control:*:*:*:*:*:*:*:*
  metadata:
    verified: true
    max-request: 1
    vendor: connectwise
    product: control
    shodan-query: html:"ContentPanel SetupWizard"
  tags: misconfig,exposure,install,connectwise,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/SetupWizard.aspx"

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - "SetupWizardPage"
          - "ContentPanel SetupWizard"
        condition: and

      - type: status
        status:
          - 200
# digest: 4a0a00473045022100e1ad5809c9fc72bb4d5db5d38c8195c03347ec03e66b141ad79d27c747fcb5800220534f0177354760c3cdadbce71915c8723682204b9683af5f4bdbbd167a2a0fde:922c64590222798bb761d5b6d8e72950