Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-31324 PoC — Missing Authorization check in SAP NetWeaver (Visual Composer development server)

Source
Associated Vulnerability
Title: Missing Authorization check in SAP NetWeaver (Visual Composer development server) (CVE-2025-31324)
Description:SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
Description
A Python-based security scanner for identifying the CVE-2025-31324 vulnerability in SAP Visual Composer systems, and detecting known Indicators of Compromise (IOCs) such as malicious .jsp.
Readme
# SAP CVE-2025-31324 Analyzer

![Visitors](https://visitor-badge.laobi.icu/badge?page_id=JonathanStross.CVE-2025-31324)

A Python-based security scanner for identifying the **CVE-2025-31324** vulnerability in SAP Visual Composer systems, and detecting known Indicators of Compromise (IOCs) such as malicious `.jsp`.

---

## 🚀 Features

- Detects vulnerable Visual Composer endpoints
- Scans for known malicious `.jsp` files (webshells)
- Multi-target scanning from a CSV file
- Custom IOC file support
- Saves results to CSV (optional)
- Optional verbosity

---

## 🛠 Requirements

- Python 3.6+
- `requests` library (installed via `requirements.txt`)

---

## 📦 Installation

```bash
# 1. Clone the repository
git clone https://github.com/youruser/CVE-2025-31324.git
cd CVE-2025-31324

# 2. Create and activate virtual environment
python3 -m venv venv
source venv/bin/activate  # On Windows: venv\Scripts\activate

# 3. Install dependencies
pip install -r requirements.txt
```

---

## 📦 File Structure

```
scan.py                 # Main scanner
targets.csv             # Input list of targets
ioc_list.txt            # Optional IOC signature list
results.csv             # Output report (if --output used)
requirements.txt        # Python dependencies
```

---

## 📄 CSV Input Format

Create a file named `targets.csv` with the following **semicolon-separated** format with IP, Port and SSL option:

```csv
192.168.1.10;50000;false
myunsafelocation.example.com;443;true
10.0.0.5;8080;false
```

- **ssl**: Use `true`, `false`, `yes`, or `no`

---

## 🕵️ IOC List Format

Create a file named `ioc_list.txt`:

```text
# Default IOCs
cache.jsp
helper.jsp
nzwcnktc.jsp

# Add your own signatures
shell.jsp
webadmin.jsp
```

---

## ⚙️ Usage

```bash
python3 scan.py --input targets.csv
```

### Optional Flags:

| Flag                 | Description                                  |
|----------------------|----------------------------------------------|
| `--iocfile`          | Path to custom IOC list (`.txt`)             |
| `--output` or `-o`   | Save results to CSV                          |
| `--verbose` or `-v`  | Enable detailed debug output                 |

### Example:

```bash
python3 scan.py --input targets.csv --iocfile ioc_list.txt --output results.csv --verbose
```

---

## 🎨 Output Explanation

The script prints a result block for each host:

```
__________________________________
✅ Target 1 : 192.168.1.10:50000
Connection: Online
Status: Not Vulnerable
IOC: None detected
__________________________________
```

### Icons:

| Icon  | Meaning                                |
|--------|----------------------------------------|
| ✅     | Safe (Not vulnerable, no IOCs)         |
| ❗     | Vulnerable, but no IOCs found          |
| 💥     | Vulnerable + IOC(s) detected          |
| ❌     | Host not reachable / connection failed |

---

## 🧪 Local Testing

To test locally, run a Python HTTP server simulating a vulnerable SAP system:

```bash
mkdir -p test/developmentserver
mkdir -p test/irj
echo "" > test/developmentserver/metadatauploader
echo "<%-- fake webshell --%>" > test/irj/cache.jsp
cd test
python3 -m http.server 8000
```

Add to `targets.csv`:
```csv
0.0.0.0;8000;false
```

---

## 🛡 Disclaimer

This tool is provided **for authorized security testing and research only**. Do not use against systems you do not own or have explicit permission to scan.

---

## 📬 Feedback

For suggestions or improvements, please open an issue or submit a PR.

---

## ⚖ License

This project is licensed under the [MIT License](LICENSE).  
You are free to use, modify, and distribute it — commercially or privately.

**Disclaimer**:  
This tool is provided **as-is**, without any warranty or guarantee.  
The authors are not responsible for any damage or legal issues caused by its usage.  
Use it only in environments where you have **explicit authorization** to scan and test systems.
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →