跳转到帖子

ManageEngine Endpoint Central Unauthenticated SAML RCE

recommended_posts

发布于
  • Members

ManageEngine Endpoint Central Unauthenticated SAML RCE

Disclosed
01/10/2023
Created
02/09/2023

Description

This exploits an unauthenticated remote code execution vulnerability that affects Zoho ManageEngine Endpoint Central and MSP versions 10.1.2228.10 and below (CVE-2022-47966). Due to a dependency to an outdated library (Apache Santuario version 1.4.1), it is possible to execute arbitrary code by providing a crafted `samlResponse` XML to the Endpoint Central SAML endpoint. Note that the target is only vulnerable if it is configured with SAML-based SSO , and the service should be active.

Author(s)

Platform

Java,Windows

Development

  • Source Code
  • History
  • 查看数 695
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…