VMware vCenter Server Virtual SAN Health Check plug-in Remote OS Command Injection Exploit

This module exploits a Java unsafe reflection and a Server Side Request Forgery vulnerabilities present in ProxygenController class via POST requests to the /ui/h5-vsan/rest/proxy/service endpoint. The deployed agent will run with the vsphere-ui user account privileges.
Exploit Platform
Product Name