Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8r38-vv5x-w6gc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon the occurrence of an alarm. An attacker can abuse this functionality by uploading a malicious script that can be executed on the remote system.

In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon the occurrence of an alarm. An attacker can abuse this functionality by uploading a malicious script that can be executed on the remote system.

EPSS

Процентиль: 83%
0.01835
Низкий

Связанные уязвимости

CVSS3: 8.8
nvd
больше 6 лет назад

In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon the occurrence of an alarm. An attacker can abuse this functionality by uploading a malicious script that can be executed on the remote system.

EPSS

Процентиль: 83%
0.01835
Низкий