Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 06:26
Type | Values Removed | Values Added |
---|---|---|
References | () https://pitstop.manageengine.com/portal/en/community/topic/unauthenticated-remote-code-execution-vulnerability-solved - Patch, Vendor Advisory | |
References | () https://www.manageengine.com/sccm-third-party-patch-management/kb/unauthenticated-remote-code-execution.html - Vendor Advisory |
Information
Published : 2021-11-11 05:15
Updated : 2024-11-21 06:26
NVD link : CVE-2021-41833
Mitre link : CVE-2021-41833
CVE.ORG link : CVE-2021-41833
JSON object : View
Products Affected
zohocorp
- manageengine_patch_connect_plus
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type