References https://nosec.org/m/share/4857.html https://stack.chaitin.com/vuldb/detail/82421acc-cfbc-42e3-97c1-8eb285e6eda8 https://cve.circl.lu/vuln/cnvd-2021-88248 https://www.tenablecloud.cn/plugins/nessus/154964 https://avd.aliyun.com/detail?id=AVD-2021-40539 https://cve.imfht.com/poc_detail/4fb2b13bf3e228c9c9233b41812b1f9a4a9cf004 https://blog.csdn.net/QTcyber/article/details/121206857 https://github.com/emadshanab/goby_poc5/blob/main/ADSelfService_Plus_RCE_CVE_2021_40539.json https://www.ddpoc.com/DVB-2021-3046.html https://www.rapid7.com/db/vulnerabilities/zoho-manageengine-adselfservice-plus-cve-2021-40539/ https://pentest-tools.com/blog/detect-zoho-rce-cve-2021-40539 https://www.microsoft.com/en-us/security/blog/2021/11/08/threat-actor-dev-0322-exploiting-zoho-manageengine-adselfservice-plus/ https://www.manageengine.com/products/self-service-password/advisory/CVE-2021-40539.html https://nvd.nist.gov/vuln/detail/cve-2021-40539 https://www.manageengine.com/products/self-service-password/kb/how-to-fix-authentication-bypass-vulnerability-in-REST-API.html
Related VulnerabilitiesPoCCVE-2022-28987: Zoho ManageEngine ADSelfService Plus 6121 - Username EnumerationPoCCVE-2022-36923: Zoho ManageEngine - getUserAPIKey Authentication BypassPoCCVE-2021-37415: Zoho ManageEngine ServiceDesk Plus - Authentication BypassPoCCVE-2022-29081: Zoho ManageEngine - Access Control BypassPoCCVE-2012-4889: ManageEngine Firewall Analyzer 7.2 - Cross-Site ScriptingPoCCVE-2015-7780: ManageEngine Firewall Analyzer <8.0 - Local File InclusionPoCCVE-2017-11512: ManageEngine ServiceDesk 9.3.9328 - Arbitrary File RetrievalPoCCVE-2018-12998: Zoho manageengine - Cross-Site ScriptingPoCCVE-2018-17283: Zoho ManageEngine OpManager - SQL InjectionPoCCVE-2020-10189: ManageEngine Desktop Central Java DeserializationPoCCVE-2020-12116: Zoho ManageEngine OpManger - Arbitrary File ReadPoCCVE-2021-37416: Zoho ManageEngine ADSelfService Plus <=6103 - Cross-Site ScriptingPoCCVE-2021-40539: Zoho ManageEngine ADSelfService Plus v6113 - Unauthenticated Remote Command Execution