vsDesk 中存在一个不安全的反序列化漏洞,允许远程攻击者获得未授权的行政管理访问权限。通过篡改应用程序配置数据,攻击者可以强制系统向任意 LDAP 服务器进行身份验证,并配置一个新的管理员账户。 请从供应商处获取补丁:https://vsdesk.ru/ 。版本 14.0402 及以上版本已包含此补丁。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet