Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-38147 PoC — Wipro Holmes Orchestrator 访问控制错误漏洞

Source
Associated Vulnerability
Title:Wipro Holmes Orchestrator 访问控制错误漏洞 (CVE-2021-38147)
Description:Wipro Holmes Orchestrator是印度Wipro公司的一个一站式应用人工智能(Ai)和自动化平台编排器。 Wipro Holmes Orchestrator 20.4.1版本存在访问控制错误漏洞,未经身份验证攻击者可以下载以前导出的Excel报告。
Description
Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to download arbitrary files, such as reports containing sensitive information, because authentication is not required for API access to processexecution/DownloadExcelFile/Domain_Credential_Report_Excel, processexecution/DownloadExcelFile/User_Report_Excel, processexecution/DownloadExcelFile/Process_Report_Excel, processexecution/DownloadExcelFile/Infrastructure_Report_Excel, or processexecution/DownloadExcelFile/Resolver_Report_Excel.
File Snapshot

id: CVE-2021-38147 info: name: Wipro Holmes Orchestrator 20.4.1 - Information Disclosure author ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.