CVE-2022-28810
Description
Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field.
Summary dbcve.org
Zoho ManageEngine ADSelfService Plus before build 6122 contains a command injection vulnerability allowing remote authenticated administrators to execute arbitrary OS commands as SYSTEM via the policy custom script feature. The presence of default administrator passwords enables unauthenticated or minimally-authenticated attackers to exploit this. Additionally, an unsanitized password field allows command injection by partially authenticated attackers.
Mitigation
Upgrade to ADSelfService Plus build 6122 or later immediately. Change all default administrator passwords and enforce strong password policies. Restrict administrative access to trusted networks and implement network segmentation.