Yo, I needed to use this exploit in a HTB machine and the only other PoC I could find was written in ruby...
I didn't wanna mess with the ruby dependancies so I just re-wrote it in python "real quick".
---
This is basically just a parser for the JSON returned by the open API endpoints, this can be replicated easily with CURL or a web browser by hitting the following endpoints: