Zoho Password Manager Pro XML-RPC Java Deserialization
Posted by deepcore on August 3, 2022 – 10:28 pm
This Metasploit module exploits a Java deserialization vulnerability in Zoho ManageEngine Pro before 12101 and PAM360 before 5510. Unauthenticated attackers can send a crafted XML-RPC request containing malicious serialized data to /xmlrpc to gain remote command execution as the SYSTEM user.
Post a reply
You must be logged in to post a comment.