Home / os / winme

Atlassian Confluence Namespace OGNL Injection

Posted on 08 June 2022

This Metasploit module exploits an OGNL injection in Atlassian Confluence servers. A specially crafted URI can be used to evaluate an OGNL expression resulting in OS command execution.

 

TOP