Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9g5v-572f-c456

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user can gain the authority of SYSTEM on the server by uploading a malicious file via the "Execute Program Action(s)" feature.

Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user can gain the authority of SYSTEM on the server by uploading a malicious file via the "Execute Program Action(s)" feature.

EPSS

Процентиль: 90%
0.05067
Низкий

Связанные уязвимости

CVSS3: 9.8
nvd
почти 7 лет назад

Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user can gain the authority of SYSTEM on the server by uploading a malicious file via the "Execute Program Action(s)" feature.

EPSS

Процентиль: 90%
0.05067
Низкий