discovered 03 Aug 2026
MSAPer
→ View on GitHubMSAPer is an automated mass exploitation tool designed for identifying and exploiting the CVE-2023-3076 vulnerability in MStore API versions below 3.9.9, which enables unauthenticated privilege escalation through mass addition of admin accounts and PHP file uploads. The tool utilizes GNU Parallel for efficient execution and requires a list of target URLs as input. Notable features include the ability to run on both Linux and Windows platforms, along with installation instructions for necessary dependencies.