CVE-2023-39912

Zoho ManageEngine ADManager Plus before 7203 allows Help Desk Technician users to read arbitrary files on the machine where this product is installed.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zohocorp:manageengine_admanager_plus:*:*:*:*:*:*:*:*

History

01 Jan 2024, 06:15

Type Values Removed Values Added
Summary Zoho ManageEngine ADManager Plus through 7202 allows admin users to download any file from the server machine via directory traversal. Zoho ManageEngine ADManager Plus before 7203 allows Help Desk Technician users to read arbitrary files on the machine where this product is installed.

06 Sep 2023, 20:24

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.9
References (MISC) https://manageengine.com - (MISC) https://manageengine.com - Product
References (MISC) https://www.manageengine.com/products/ad-manager/admanager-kb/cve-2023-39912.html - (MISC) https://www.manageengine.com/products/ad-manager/admanager-kb/cve-2023-39912.html - Vendor Advisory
First Time Zohocorp
Zohocorp manageengine Admanager Plus
CWE CWE-22
CPE cpe:2.3:a:zohocorp:manageengine_admanager_plus:*:*:*:*:*:*:*:*

31 Aug 2023, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-31 23:15

Updated : 2024-02-28 20:33


NVD link : CVE-2023-39912

Mitre link : CVE-2023-39912

CVE.ORG link : CVE-2023-39912


JSON object : View

Products Affected

zohocorp

  • manageengine_admanager_plus
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')