#VU56414 Improper access control in Zoho ManageEngine ADSelfService Plus - CVE-2021-40539
Published: September 9, 2021 / Updated: November 24, 2021
Zoho ManageEngine ADSelfService Plus
Zoho Corporation
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper access restrictions to the "/RestAPI/LogonCustomization" and "/RestAPI/Connection" REST API endpoints. A remote non-authenticated attacker can send specially HTTP requests to the aforementioned REST API endpoints and execute arbitrary code on the system.
Note, the vulnerability is being actively exploited in the wild.