CVE-2021-21973: VMware vSphere – Server-Side Request Forgery

CVE-2021-21973: VMware vSphere - Server-Side Request Forgery-渗透云记 - 专注于网络安全与技术分享
CVE-2021-21973: VMware vSphere – Server-Side Request Forgery
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2021-21973: Vmware vSphere – Server-Side Request Forgery

漏洞描述

VMware vSphere (HTML5) is susceptible to server-side request forgery due to improper validation of URLs in a vCenter Server plugin. An attacker with network access to port 443 can exploit this issue by sending a POST request to the plugin. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l, and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享