Attack And Defense [CVE-2022–26180]

Jay Sharma
Jul 23, 2022

--

In this Blog we are solving https://attackdefense.pentesteracademy.com/challengedetails?cid=2405&utm_source=lp&utm_medium=referral&utm_campaign=labsprint

Attack and Defense

Let’s start with basic recon

We already have the credential and we try to login with it

Now let’s try to exploit CVE-2022–26180 and I google it found some exploit db link https://www.exploit-db.com/exploits/50854 as mention in exploit I change the URL and Submit the request

file with html code

the full name, email and password but i missed the put ID of user after realizing again i change the user ID and submit the request again.

We now successfully change the account details.

Hope you like my small blog.

Get Start with you career in Cyber security click here

Follow me on twitter DA3M0N
Jay Sharma

--

--

Jay Sharma
Jay Sharma

No responses yet