Smart Time Plus RCE – CVE-2024-53543
The Software Smart Time Plus < 8.6 contains several vulnerabilities: which can be chained to achieve unauthenticated remote code execution as SYSTEM on the Windows host. Background and Research During a pentest I stumbled across the following web service on port 443: Smart Time Plus is a time tracking tool developed and published by the
Continue Reading „Smart Time Plus RCE – CVE-2024-53543“