ID:7037 - Exploit for Improper access control in Zoho ManageEngine ADSelfService Plus - CVE-2021-40539
Published: November 24, 2021
Zoho ManageEngine ADSelfService Plus
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper access restrictions to the "/RestAPI/LogonCustomization" and "/RestAPI/Connection" REST API endpoints. A remote non-authenticated attacker can send specially HTTP requests to the aforementioned REST API endpoints and execute arbitrary code on the system.
Note, the vulnerability is being actively exploited in the wild.