transformeroptimus/superagi
cpe:2.3:a:superagi:superagi:*:*:*:*:*:*:*
- 0.0.14
A path traversal vulnerability has been identified in the file upload feature of transformeroptimus/superagi, version 0.0.14. This vulnerability allows attackers to upload arbitrary files to the server, which could result in remote code execution or overwriting any file on the server.
Exploitation of this vulnerability could lead to remote code execution or unauthorized file overwriting on the server.
To reproduce this vulnerability, upload a text file through the Resource Manager's file upload feature. Intercept the request with Burp Suite and modify it to include a path traversal payload that targets the user's SSH authorized_keys file. After sending the modified request, the uploaded content will be written to the authorized_keys file, allowing SSH access to the server without a password.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.