Files
CVEs-PoC/2021/CVE-2021-25924.md
T
2025-09-29 21:09:30 +02:00

20 lines
1.2 KiB
Markdown

### [CVE-2021-25924](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25924)
![](https://img.shields.io/static/v1?label=Product&message=gocd&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=19.6.0%2C%2019.7.0%2C%2019.8.0%2C%2019.9.0%2C%2019.10.0%2C%2019.11.0%2C%2019.12.0%2C%2020.1.0%2C%2020.2.0%2C%2020.3.0%2C%2020.4.0%2C%2020.5.0%2C%2020.6.0%2C%2020.7.0%2C%2020.8.0%2C%2020.9.0%2C%2020.10.0%2C%2021.1.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Cross-Site%20Request%20Forgery&color=brightgreen)
### Description
In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/go/api/config/backup` endpoint. An attacker can trick a victim to click on a malicious link which could change backup configurations or execute system commands in the post_backup_script field.
### POC
#### Reference
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25924%2C
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25924,
#### Github
- https://github.com/20142995/nuclei-templates
- https://github.com/cyb3r-w0lf/nuclei-template-collection