First published: Sat Mar 29 2014(Updated: )
Properties.do in ZOHO ManageEngine OpStor before build 8500 does not properly check privilege levels, which allows remote authenticated users to obtain Admin access by using the name parameter in conjunction with a true value of the edit parameter.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Opstor | <=8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.