Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-3897 PoC — 42Gears SureMDM 安全漏洞

Source
Associated Vulnerability
Title:42Gears SureMDM 安全漏洞 (CVE-2023-3897)
Description:42gears Mobility Systems 42Gears SureMDM是美国42gears Mobility Systems公司的一套用于移动设备的资产管理平台。该平台主要用于监控和管理企业移动设备。 42gears Mobility Systems 42Gears SureMDM 6.31 及之前版本存在安全漏洞,该漏洞源于在 Windows本地部署 SureMDM Solution 时,可以绕过验证码,攻击者利用该漏洞可以通过错误消息枚举本地用户信息。
Readme
# CVE-2023-3897
Username enumeration is possible through Bypassing CAPTCHA in On-premise SureMDM Solution on Windows deployment allows attacker to enumerate local user information via error message. <br /> <br />
This issue affects SureMDM On-premise: 6.31 and below version 

- https://nvd.nist.gov/vuln/detail/CVE-2023-3897
- https://www.42gears.com/trust-center/information-security/security-advisories/42g-2023-003/
- https://www.exploit-db.com/exploits/51804

```
searchsploit -x multiple/webapps/51804.txt
```
File Snapshot

[4.0K] /data/pocs/0e738ce5bec94ad6749731b6527aa6e0cd43e670 ├── [1.6K] exploit.py └── [ 516] README.md 0 directories, 2 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.