CVE-2019-15104
HIGHManageEngine Applications Manager 12.0-13.9 - SQL Injection via NewThresholdConfiguration.jsp resourceid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-15104. PoCs published by AkkuS.
AI-analyzed exploit summary This Metasploit module exploits SQL injection and command injection vulnerabilities in ManageEngine OpManager 12.4x to create an admin user and achieve remote command execution. It uploads a malicious file and executes it via the 'Execute Program Action(s)' feature.
Description
An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently upload a malicious file using the "Execute Program Action(s)" feature.
Exploits (1)
This Metasploit module exploits SQL injection and command injection vulnerabilities in ManageEngine OpManager 12.4x to create an admin user and achieve remote command execution. It uploads a malicious file and executes it via the 'Execute Program Action(s)' feature.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H