What happened
SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.
Affected versions
NetWeaver: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
PoC-in-GitHub · rxerium/CVE-2025-31324SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.★ 4rxerium2025-04-25CandidatePoC-in-GitHub · redrays-io/CVE-2025-31324CVE-2025-31324, SAP Exploit★ 25redrays-io2025-04-27CandidatePoC-in-GitHub · Onapsis/Onapsis_CVE-2025-31324_Scanner_Tools★ 12Onapsis2025-04-27CandidatePoC-in-GitHub · moften/CVE-2025-31324SAP PoC para CVE-2025-31324★ 0moften2025-04-28CandidatePoC-in-GitHub · moften/CVE-2025-31324-NUCLEINuclei template for cve-2025-31324 (SAP)★ 1moften2025-04-28CandidatePoC-in-GitHub · Alizngnc/SAP-CVE-2025-31324SAP NetWeaver Unauthenticated Remote Code Execution★ 0Alizngnc2025-04-28CandidatePoC-in-GitHub · ODST-Forge/CVE-2025-31324_PoCProof-of-Concept for CVE-2025-31324: Unauthenticated upload in SAP NetWeaver Visual Composer Metadata Uploader★ 7ODST-Forge2025-04-28CandidatePoC-in-GitHub · abrewer251/CVE-2025-31324_PoC_SAPProof-of-Concept for CVE-2025-31324: Unauthenticated upload in SAP NetWeaver Visual Composer Metadata Uploader★ 0abrewer2512025-04-29CandidatePoC-in-GitHub · BlueOWL-overlord/Burp_CVE-2025-31324Python-based Burp Suite extension is designed to detect the presence of CVE-2025-31324★ 0BlueOWL-overlord2025-04-30CandidatePoC-in-GitHub · nullcult/CVE-2025-31324-File-UploadA totally unauthenticated file-upload endpoint in Visual Composer lets anyone drop arbitrary files (e.g., a JSP web-shell) onto the server.★ 2nullcult2025-04-30CandidatePoC-in-GitHub · respondiq/jsp-webshell-scanner🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.★ 1respondiq2025-04-30CandidatePoC-in-GitHub · JonathanStross/CVE-2025-31324A Python-based security scanner for identifying the CVE-2025-31324 vulnerability in SAP Visual Composer systems, and detecting known Indicators of Compromise (IOCs) such as malicious .jsp.★ 1JonathanStross2025-04-30CandidatePoC-in-GitHub · Onapsis/Onapsis-Mandiant-CVE-2025-31324-Vuln-Compromise-AssessmentCVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool★ 9Onapsis2025-05-01CandidatePoC-in-GitHub · rf-peixoto/sap_netweaver_cve-2025-31324-Research Purposes only★ 5rf-peixoto2025-05-06CandidatePoC-in-GitHub · NULLTRACE0X/CVE-2025-31324★ 9NULLTRACE0X2025-05-07CandidatePoC-in-GitHub · nairuzabulhul/nuclei-template-cve-2025-31324-checksap-netweaver-cve-2025-31324-check★ 1nairuzabulhul2025-05-08CandidatePoC-in-GitHub · sug4r-wr41th/CVE-2025-31324SAP NetWeaver Visual Composer Metadata Uploader <= 7.50 CVE-2025-31324 PoC★ 0sug4r-wr41th2025-05-10CandidatePoC-in-GitHub · antichainalysis/sap-netweaver-0day-CVE-2025-31324sap netweaver 0day poc by shinyhunters (scattered lapsus$ hunters) affecting all 7.x CVE-2025-31324★ 22antichainalysis2025-08-15CandidatePoC-in-GitHub · harshitvarma05/CVE-2025-31324-Exploits★ 0harshitvarma052025-08-20CandidatePoC-in-GitHub · aristois913/CVE-2025-31324Proof-of-Concept 0day for SAP NetWeaver created by ShinyHunters★ 3aristois9132026-01-12CandidatePoC-in-GitHub · HKenzoKimura/CVE-2025-31324★ 0HKenzoKimura2026-09-06CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.