Atlassian Confluence SafeParametersInterceptor Broken Access Control Vulnerability Remote Code Execution Exploit

This module uses broken access control vulnerability via SafeParametersInterceptor class in Atlassian Confluence to create a new admin user in the target system using the provided credentials. If no credentials are provided, it will generate a random one. This admin account is then used to upload a Servlet plugin JAR file to deploy an agent. The deployed agent will run with the same privileges than the Confluence instance.
Exploit Platform
Exploit Type
Product Name