Sploitus

Exploit for Deserialization of Untrusted Data in Apache Tomcat

githubexploit Β· 2025-08-06

Exploit Code

README45 lines
## https://sploitus.com/exploit?id=D101B3E0-C8EE-5ED2-BC87-B5E1DAAA2D9B
# CVE-2025-24813 Exploit Toolkit

This is an advanced and automated exploitation tool for **CVE-2025-24813**, targeting Apache Tomcat servers vulnerable to insecure session deserialization.

## πŸ” Features
- Multi-target scanning from file or single URL (`--targets` / `--url`)
- Automatic gadget chain testing (CommonsCollections1-7, BeanShell, Spring, etc.)
- OS detection and post-exploitation payloads (Linux/Windows)
- Session ID discovery from common endpoints
- Verbose logging to both console and file
- TLS (HTTPS) support with optional SSL verification disabling

## βš™οΈ Usage

```bash
# Single target
python3 exploit_cve_2025_24813.py \
  --url http://target:8080 \
  --ysoserial ysoserial.jar \
  --no-ssl-verify

# Multiple targets from file
python3 exploit_cve_2025_24813.py \
  --targets targets.txt \
  --ysoserial ysoserial.jar \
  --no-ssl-verify
```

## πŸ“₯ Requirements

    Python 3.6+

    Java Runtime (for ysoserial)

    ysoserial Java binary

## ⚠️ Legal Disclaimer

This tool is provided for educational and authorized security testing purposes only. Any unauthorized use against systems you do not own or have explicit permission to test is strictly prohibited and may be illegal.
πŸ“š Credits

This project was inspired by a public PoC published under the Apache License 2.0.
Original PoC author: absholi7ly
Enhanced and rewritten by mehrdad mirabi