Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Unauthorized RCE in VMware vCenter

Summary

Technical details of the VMware vSphere Client flaws found in fall 2020: an unauthorized file upload in the vropspluginui plugin leading to RCE (CVE-2021-21972) and an unauthenticated SSRF (CVE-2021-21973), both exploitable without credentials.
Published
Collected

original ↗

Related coverage

back