CVE-2024-23738# CVE-2024-23738
An issue in Postman through 10.22 on macOS allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.
There is a tool designed to automate the process of searching for vulnerabilities in electron: https://github.com/r3ggi/electroniz3r
<img width="1277" alt="image" src="https://github.com/V3x0r/CVE-2024-23738/assets/83291215/19665649-67b9-4e48-90ea-af64a9fe7ed3">
With this tool, we can check if the App is Vulnerable:
<img width="710" alt="image" src="https://github.com/V3x0r/CVE-2024-23738/assets/83291215/d2465158-af23-478b-b975-25c1f2bc90ed">
After validation, we can inject our code, and get a shell
<img width="843" alt="image" src="https://github.com/V3x0r/CVE-2024-23738/assets/83291215/cd658b45-7fdd-4e12-bf75-61a8efb2ff85">
Enjoy Your Shell :)
[4.0K] /data/pocs/de6ac4c04d6e59341db20a4c4e1af4cd9ed5b902
└── [ 855] README.md
0 directories, 1 file