====================================================================================================================================
# Title : ERPGo SaaS CRM v3.3 Arbitrary File Upload Vulnerability
# Author : indoushka
# Tested on : windows 10 Francais V.(Pro) / browser : Mozilla firefox 103.0(64-bit)
| # Vendor : https://codecanyon.net/item/erpgo-saas-all-in-one-business-erp-with-project-account-hrm-crm-pos/33263426 |
# Dork : “ERPGo SaaS” login
“Attention, the new currency,” The easier the writing appears the more work the writer put in. |
====================================================================================================================================
Poc :
[+] Searching In Google Or Other Search Engines.
[+] Use Payload : https://erpgo.127.0.0.1/ERPGo/register <====| Register New account
[+] Go to your membership profile and upload a malicious file instead of an image <===| https://erpgo.127.0.0.1/erpgo-saas/profile
[+] Your Ev!l = https://erpgo.127.0.0.1/erpgo-saas/storage/uploads/avatar/zip_1671699428.php
Greetings to :=========================================================================================================================
|
|
=======================================================================================================================================