CVE-2023-35854
CRITICALManageEngine ADSelfService Plus <= 6113 - Authentication Bypass via Session Token Theft
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-35854. PoCs published by bluestarry33.
AI-analyzed exploit summary This PoC exploits CVE-2023-35854, an authentication bypass vulnerability in an unspecified software, to upload a JSP webshell or a Java class payload for remote code execution. It includes multiple stages for checking vulnerability, uploading payloads, and executing commands.
Description
Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator. NOTE: the vendor's perspective is that they have "found no evidence or detail of a security vulnerability."
Exploits (1)
This PoC exploits CVE-2023-35854, an authentication bypass vulnerability in an unspecified software, to upload a JSP webshell or a Java class payload for remote code execution. It includes multiple stages for checking vulnerability, uploading payloads, and executing commands.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H