Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

add plugin CVE-2021-40539 ADSelfService Plus authentication bypass vulnerability #216

Merged

Conversation

hh-hunter
Copy link
Contributor

Hi @magl0, #189 is complete, it was originally published as an authentication bypass but on 6 November details of a vulnerability exploit for RCE appeared, this vulnerability is more impactful and can gain access to the server, please check it out. Thanks!

As he is a Windows environment, I cannot provide a docker environment, but I can provide two different versions of the binaries that you just need to install to complete the vulnerability verification.

Affected Versions

https://archives2.manageengine.com/self-service-password/6112/

Unaffected version

https://archives2.manageengine.com/self-service-password/6114/

All you need to do is download ManageEngine_ADSelfService_Plus.exe and install it.

   create detector cve_2021_40539 plugin
@copybara-service copybara-service bot merged commit 6c22591 into google:master Mar 10, 2022
@hh-hunter hh-hunter deleted the adselfservice_plus_cve_2021_40539 branch May 6, 2022 06:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants