Zoho Password Manager Pro XML-RPC Java Deserialization

Discussion in 'News Aggregator' started by Packet Storm, 4 Aug 2022.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module exploits a Java deserialization vulnerability in Zoho ManageEngine Pro before 12101 and PAM360 before 5510. Unauthenticated attackers can send a crafted XML-RPC request containing malicious serialized data to /xmlrpc to gain remote command execution as the SYSTEM user.

    Continue reading...
     

Share This Page

Loading...