ID:7119 - Exploit for Improper Authentication in Zoho ManageEngine ServiceDesk Plus - CVE-2021-44077
Published: December 8, 2021
Zoho ManageEngine ServiceDesk Plus
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to compromise the affected system..
The vulnerability exists due to missing authentication, related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration. A remote non-authenticated attacker can send a specially crafted request to the API endpoint, bypass authentication process and execute arbitrary code on the system.