Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-42671 PoC — Engineers Online Portal 访问控制错误漏洞

Source
Associated Vulnerability
Title:Engineers Online Portal 访问控制错误漏洞 (CVE-2021-42671)
Description:Engineers Online Portal是开源的一个在线门户。是使用PHP、MySQL 数据库、HTML、CSS、Javascript、jQuery、Ajax、Bootstrap 和一些其他库开发的。 Engineers Online Portal 存在访问控制错误漏洞,该漏洞源于PHP中Sourcecodester Engineers Online Portal中存在一个错误的访问控制漏洞。攻击者可利用该漏洞绕过访问控制,在不需要认证或授权的情况下访问上传到web服务器的所有文件。
Description
CVE-2021-42671 - Broken access control vulnerability in the Engineers online portal system. 
Readme
# CVE-2021-42671
CVE-2021-42671 - Broken access control vulnerability in the Engineers online portal system. 

# Technical description:
A broken access control vulnerability exists in the Engineers Online Portal. An attacker can leverage this vulnerability in order to bypass access controls and get his hands on all the files uploaded to the web server without the need of authentication or authorization. 

Vulnerable domain - http://localhost/nia_munoz_monitoring_system/admin/uploads/

# Proof of concept (Poc) -
Navigate to http://localhost/nia_munoz_monitoring_system/admin/uploads/ in order to bypass the access control of the target web server. 
As a result you can reach sensetive information stored on the web server uploads folder. 

![CVE-2021-42671](https://user-images.githubusercontent.com/93016131/140196897-9f334ed2-a477-4b5e-a806-57a11d17a615.gif)

# References - 
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42671

https://nvd.nist.gov/vuln/detail/CVE-2021-42671

# Discovered by - 
Alon Leviev(0xDeku), 22 October, 2021. 
File Snapshot

[4.0K] /data/pocs/c35ae9858766b890ff8a29214499a07a07dea54b └── [1.0K] README.md 0 directories, 1 file
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.