Openfire 4.7.4, vulnerable to CVE-2023-32315: a traversal from the /setup/ path (encoded as %u002e) reaches admin console pages without a login, so an anonymous user creates an administrator and then uploads a plugin to run code.
Not startedDockercommit 7164a10x86_64 · aarch64Secret
Exploit CVE-2023-32315 to become an Openfire administrator and get a shell.
The brief for this lab lives in its repository.