watchtowrlabs / connectwise-screenconnect_auth-bypass-add-user-poc

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

CVE-2024-1708 and CVE-2024-1709

A Proof of Concept developed by @watchTowr to exploit an authentication bypass to add a new administrative user in ConnectWise ScreenConnect. This is the first step in a trivial Remote Command Execution chain.

Follow the watchTowr Labs Team for our Security Research

About


Languages

Language:Python 100.0%