CVE-2022-28219

CRITICAL EXPLOITED NUCLEI LAB

ManageEngine ADAudit Plus CVE-2022-28219

Title source: metasploit

Description

Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.

Exploits (4)

nomisec WORKING POC 45 stars
by horizon3ai · remote
https://github.com/horizon3ai/CVE-2022-28219
nomisec WORKING POC 3 stars
by rbowes-r7 · poc
https://github.com/rbowes-r7/manageengine-auditad-cve-2022-28219
nomisec STUB 1 stars
by aeifkz · poc
https://github.com/aeifkz/CVE-2022-28219-Like
metasploit WORKING POC EXCELLENT
by Naveen Sunkavally, Ron Bowes · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/manageengine_adaudit_plus_cve_2022_28219.rb

Nuclei Templates (1)

Zoho ManageEngine ADAudit Plus <7600 - XML Entity Injection/Remote Code Execution
CRITICALVERIFIEDby dwisiswant0
Shodan: http.title:"ADAudit Plus" || http.title:"ManageEngine - ADManager Plus" || http.title:"adaudit plus" || http.title:"manageengine - admanager plus"
FOFA: title="adaudit plus" || http.title:"manageengine - admanager plus"

Scores

CVSS v3 9.8
EPSS 0.9420
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2023-11-13
CWE
CWE-611
Status published
Products (2)
zohocorp/manageengine_adaudit_plus 7.0 7000 (13 CPE variants)
zohocorp/manageengine_adaudit_plus < 6.0
Published Apr 05, 2022
Tracked Since Feb 18, 2026