NA

CVE-2022-47966

Vulnerability Summary

This Metasploit module exploits an unauthenticated remote code execution vulnerability that affects Zoho ManageEngine AdSelfService Plus versions 6210 and below. Due to a dependency to an outdated library (Apache Santuario version 1.4.1), it is possible to execute arbitrary code by providing a crafted samlResponse XML to the ADSelfService Plus SAML endpoint. Note that the target is only vulnerable if it has been configured with SAML-based SSO at least once in the past, regardless of the current SAML-based SSO status.

Exploits

This Metasploit module exploits an unauthenticated remote code execution vulnerability that affects Zoho ManageEngine AdSelfService Plus versions 6210 and below Due to a dependency to an outdated library (Apache Santuario version 141), it is possible to execute arbitrary code by providing a crafted samlResponse XML to the ADSelfService Plus SAML ...
This Metasploit module exploits an unauthenticated remote code execution vulnerability that affects Zoho ManageEngine ServiceDesk Plus versions 14003 and below (CVE-2022-47966) Due to a dependency to an outdated library (Apache Santuario version 141), it is possible to execute arbitrary code by providing a crafted samlResponse XML to the Service ...
This Metasploit module exploits an unauthenticated remote code execution vulnerability that affects Zoho ManageEngine Endpoint Central and MSP versions 101222810 and below (CVE-2022-47966) Due to a dependency to an outdated library (Apache Santuario version 141), it is possible to execute arbitrary code by providing a crafted samlResponse XML ...