Post

Hue Background Editor Remote Command Execution Vulnerability

Hue Background Editor Remote Command Execution Vulnerability

Hue Backstage Editor Remote Command Execution Vulnerability

Vulnerability Description

There is a command execution vulnerability in Hue background editor. Attackers can achieve the purpose of command execution by editing and uploading xxx.sh files.

Vulnerability Impact

Hue backend editor</span>

Network surveying and mapping

Vulnerability reappears

The login page is as follows

img

Upload and edit the file as the command to execute

img

Click the following steps to execute the command you want to execute

img

This post is licensed under CC BY 4.0 by the author.