Zoho ManageEngine ADSelfService Plus... CVE-2022-28810

7.1 AV AC AU C I A
发布: 2022-04-18
修订: 2024-11-21

Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field.

0%
暂无可用Exp或PoC
当前有24条受影响产品信息