
Proof-of-concept exploit for CVE-2021-45026 targeting Rocket Software Zena. Chains stored XSS to remote code execution via REST API task injection on the webconfig interface.
Rocket SoftwareのZenaアプリケーション v. 4.2.1 向けエクスプロイトPOC - 保存型XSSからRCE
https://phoenix-sec.io/2022/06/17/Zena-CookieMonsteRCE.html
POCのプロセス:
実行方法: