6.5
CVSSv2

CVE-2020-11531

Published: 08/05/2020 Updated: 18/05/2020
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

The DataEngine Xnode Server application in Zoho ManageEngine DataSecurity Plus before 6.0.1 does not validate the database schema name when handling a DR-SCHEMA-SYNC request. This allows an authenticated malicious user to execute code in the context of the product by writing a JSP file to the webroot directory via directory traversal.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zohocorp manageengine adaudit plus

zohocorp manageengine datasecurity plus

Exploits

ManageEngine DataSecurity Plus versions prior to 601 and ADAudit Plus versions prior to 603 suffers from a path traversal vulnerability that can lead to remote code execution ...