Skip to content

Access Control: Malwared BYOB - Unauthenticated Remote Code Execution

Identifier: malwared_byob_rce

Scanner Support

GraphQL Scanner REST Scanner WebApp Scanner ASM Scanner Automated Pentest

Description

Malwared BYOB allows unauthenticated remote code execution, potentially giving attackers full control over the server.

How we test: We test for unauthenticated remote code execution vulnerabilities in Malwared BYOB by injecting malicious payloads and analyzing responses to detect if arbitrary code can be executed without authentication.

Reference:

Configuration

Example

Example configuration:

---
security_tests:
  malwared_byob_rce:
    skip: false

Reference

skip

Type: boolean

Skip the test if true.