sap-netweaver-cve-2025-31324-check
Research Purposes only
Scanner and exploit for CVE-2025-3248
CVE-2025-31324 vulnerability and compromise assessment tool
A Python-based security scanner for identifying the CVE-2025-31324 vulnerability in SAP Visual Composer systems, and detecting known Indicators of Compromise (IOCs) such as malicious .jsp.
🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.
A totally unauthenticated file-upload endpoint in Visual Composer lets anyone drop arbitrary files (e.g., a JSP web-shell) onto the server.
Python-based Burp Suite extension is designed to detect the presence of CVE-2025-31324
CVE-2021-42287/CVE-2021-42278/OTHER Scanner & Exploiter.
Unauthenticated upload in SAP NetWeaver Visual Composer Metadata Uploader
Proof-of-Concept for CVE-2025-31324: Unauthenticated upload in SAP NetWeaver Visual Composer Metadata Uploader
Proof-of-Concept for CVE-2025-31324: Unauthenticated upload in SAP NetWeaver Visual Composer Metadata Uploader
SAP NetWeaver Unauthenticated Remote Code Execution
Nuclei template for cve-2025-31324 (SAP)
SAP PoC para CVE-2025-31324
Whitehat school_Docker assignement_CVE-2019-19781_PoC
CVE-2025-31324, SAP Exploit
CVE-2025-3248 Langflow 사전 인증 원격 코드 실행 취약점 PoC
CVE-2021-42287/CVE-2021-42278/OTHER Scanner & Exploiter.
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.