CVE-2021-36981
HIGHverinice < 1.22.2 - Authenticated Remote Code Execution via Unsafe Java Deserialization
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-36981. PoCs published by 0xBrAinsTorM.
AI-analyzed exploit summary This repository contains a functional Python script that exploits CVE-2021-36981, an unsafe Java deserialization vulnerability in Verinice.Pro 1.22.1. The script uses ysoserial to generate gadgets and sends them to a target endpoint, supporting both brute-force and targeted exploitation.
Description
In the server in SerNet verinice before 1.22.2, insecure Java deserialization allows remote authenticated attackers to execute arbitrary code.
Exploits (1)
This repository contains a functional Python script that exploits CVE-2021-36981, an unsafe Java deserialization vulnerability in Verinice.Pro 1.22.1. The script uses ysoserial to generate gadgets and sends them to a target endpoint, supporting both brute-force and targeted exploitation.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H