NA

CVE-2020-21642

Published: 15/08/2022 Updated: 16/08/2022
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus prior to 4350 allows remote malicious users to run arbitrary code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zohocorp manageengine analytics plus 2.9

zohocorp manageengine analytics plus 3.0

zohocorp manageengine analytics plus 3.1

zohocorp manageengine analytics plus 3.2

zohocorp manageengine analytics plus 3.3

zohocorp manageengine analytics plus 3.4

zohocorp manageengine analytics plus 3.5

zohocorp manageengine analytics plus 3.6

zohocorp manageengine analytics plus 3.7

zohocorp manageengine analytics plus 3.8

zohocorp manageengine analytics plus 3.9

zohocorp manageengine analytics plus 4.0

zohocorp manageengine analytics plus 4.1

zohocorp manageengine analytics plus 4.2

zohocorp manageengine analytics plus 4.3