# CVE-2024-54761 BigAnt Office Messenger 5.6.06 RCE via SQL Injection
The SQL injection vulnerability in BigAnt Messenger causes the RCE vulnerability
# Exploit
We extract the database version used in the 'dev_code' parameter exposed to SQL injection

Thanks to the wrong configuration in SQL, we can upload webshell to the target using SQL stack queries.

Proof of command injection:


# Timeline
31-10-2024: Submitted vulnerabilities to vendor via email
31-10-2024: Emailed vendor, no response
15-11-2024: Emailed vendor, no response
15-11-2024: Requested CVEs
# Reference
https://www.bigantsoft.com
[4.0K] /data/pocs/b6d91f5232179bb9ddb0d8cb5d3fdd50fc2a551e
└── [ 986] README.md
0 directories, 1 file