ID:10416 - Exploit for Embedded malicious code (backdoor) in Endpoint Manager - CVE-2021-44529
Published: August 16, 2024
Endpoint Manager
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to gain unauthorized access to the application.
The vulnerability exists due to presence of embedded malicious functionality in the application code (aka backdoor) within the "/opt/landesk/broker/webroot/lib/csrf-magic.php" file. A remote non-authenticated attacker can set specially crafted cookies and gain unauthorized access to the application.
Note, the vulnerability patched in 2021 by Ivanti is considered a backdoor.