Proof of Concept exploit for CVE‑2021‑43857: Authenticated Remote Code Execution in Gerapy (<0.9.8). Updated and automated version of the original Exploit‑DB PoC for educational and authorized testing purposes only.
# Gerapy CVE-2021-43857 (Authenticated RCE)
This repository contains a proof of concept exploit for **CVE-2021-43857**,
a Remote Code Execution vulnerability affecting **Gerapy < 0.9.8**.
This is an **updated version** of the [original Exploit-DB PoC](https://www.exploit-db.com/exploits/50640),
with bug fixes and automation for easier reproduction in authorized testing environments.
⚠️ **Disclaimer**:
This code is published **for educational and authorized penetration testing only**.
Do not use against systems without explicit permission.
The author takes no responsibility for misuse.
## Features
- Automates login with default credentials
- Automatically creates a project (if needed)
- Sends reverse shell payload
- Starts a Netcat listener automatically
## Usage
```bash
python3 exploit.py -t <TARGET_IP> -p <TARGET_PORT> -L <LOCAL_IP> -P <LOCAL_PORT>
```
## Requirements
1. Python 3.x
2. requests and pyfiglet (pip install requests pyfiglet)
3. Netcat (nc)
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view