SAP NetWeaver Visual Composer Metadata Uploader是德国思爱普(SAP)公司的一个用于辅助建模的工具。 SAP NetWeaver Visual Composer Metadata Uploader存在代码问题漏洞,该漏洞源于授权不当,可能导致上传恶意可执行文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SAP_SE | SAP NetWeaver (Visual Composer development server) | VCFRAMEWORK 7.50 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP NetWeaver (Visual Composer development server) | VCFRAMEWORK 7.50 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-31324.yaml | POC Details |
| 2 | SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system. | https://github.com/rxerium/CVE-2025-31324 | POC Details |
| 3 | CVE-2025-31324, SAP Exploit | https://github.com/redrays-io/CVE-2025-31324 | POC Details |
| 4 | None | https://github.com/Onapsis/Onapsis_CVE-2025-31324_Scanner_Tools | POC Details |
| 5 | SAP PoC para CVE-2025-31324 | https://github.com/moften/CVE-2025-31324 | POC Details |
| 6 | Nuclei template for cve-2025-31324 (SAP) | https://github.com/moften/CVE-2025-31324-NUCLEI | POC Details |
| 7 | SAP NetWeaver Unauthenticated Remote Code Execution | https://github.com/Alizngnc/SAP-CVE-2025-31324 | POC Details |
| 8 | Proof-of-Concept for CVE-2025-31324: Unauthenticated upload in SAP NetWeaver Visual Composer Metadata Uploader | https://github.com/ODST-Forge/CVE-2025-31324_PoC | POC Details |
| 9 | Proof-of-Concept for CVE-2025-31324: Unauthenticated upload in SAP NetWeaver Visual Composer Metadata Uploader | https://github.com/abrewer251/CVE-2025-31324_PoC_SAP | POC Details |
| 10 | Unauthenticated upload in SAP NetWeaver Visual Composer Metadata Uploader | https://github.com/Pengrey/CVE-2025-31324 | POC Details |
| 11 | Python-based Burp Suite extension is designed to detect the presence of CVE-2025-31324 | https://github.com/BlueOWL-overlord/Burp_CVE-2025-31324 | POC Details |
| 12 | A totally unauthenticated file-upload endpoint in Visual Composer lets anyone drop arbitrary files (e.g., a JSP web-shell) onto the server. | https://github.com/nullcult/CVE-2025-31324-File-Upload | POC Details |
| 13 | 🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324. | https://github.com/respondiq/jsp-webshell-scanner | POC Details |
| 14 | A Python-based security scanner for identifying the CVE-2025-31324 vulnerability in SAP Visual Composer systems, and detecting known Indicators of Compromise (IOCs) such as malicious .jsp. | https://github.com/JonathanStross/CVE-2025-31324 | POC Details |
| 15 | CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool | https://github.com/Onapsis/Onapsis-Mandiant-CVE-2025-31324-Vuln-Compromise-Assessment | POC Details |
| 16 | Research Purposes only | https://github.com/rf-peixoto/sap_netweaver_cve-2025-31324- | POC Details |
| 17 | None | https://github.com/NULLTRACE0X/CVE-2025-31324 | POC Details |
| 18 | sap-netweaver-cve-2025-31324-check | https://github.com/nairuzabulhul/nuclei-template-cve-2025-31324-check | POC Details |
| 19 | SAP NetWeaver Visual Composer Metadata Uploader <= 7.50 CVE-2025-31324 PoC | https://github.com/sug4r-wr41th/CVE-2025-31324 | POC Details |
| 20 | sap netweaver 0day poc by shinyhunters (scattered lapsus$ hunters) affecting all 7.x CVE-2025-31324 | https://github.com/antichainalysis/sap-netweaver-0day-CVE-2025-31324 | POC Details |
| 21 | None | https://github.com/harshitvarma05/CVE-2025-31324-Exploits | POC Details |
| 22 | Proof-of-Concept 0day for SAP NetWeaver created by ShinyHunters | https://github.com/aristois913/CVE-2025-31324 | POC Details |
No public POC found.
Login to generate AI POCNo comments yet