got 0day?
  • Home
Subscribe
Tagged

Lepide

A collection of 1 post

(0Day) Lepide AD Self-Service - forced browsing to RCE
ZDI-21-354

(0Day) Lepide AD Self-Service - forced browsing to RCE

TLDR Lepide AD Self-Service (LADSS) is vulnerable to a forced browsing issue that allows an unauthenticated actor to download an encrypted backup, however the backup is encrypted with a static key that can be extracted from the application code. Successful decryption gives the actor access to cleartext credentials which can

  • ⠝⠁⠃⠑⠑⠇ ⠁⠓⠍⠑⠙ (Nabeel Ahmed)
⠝⠁⠃⠑⠑⠇ ⠁⠓⠍⠑⠙ (Nabeel Ahmed) May 20, 2021 • 5 min read
got 0day? © 2026
Powered by Ghost