CVE-2017-11561: Malicious File Upload
Published May 23, 2019
·Updated
An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Alarm" section. This functionality can be abused by a malicious user by uploading a web shell.
Affected Software
1 affected component
ZohoCorp ManageEngine OpManager=12.2
Event History
May 23, 2019
CVE Published
via MITRE·03:32 PM
Data Sourced
via MITRE·03:32 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2017-11561.
2
What is the severity of CVE-2017-11561?
The severity of CVE-2017-11561 is medium with a severity value of 6.5.
3
What software is affected by CVE-2017-11561?
ZOHO ManageEngine OpManager version 12.2 is affected by CVE-2017-11561.
4
What is the impact of CVE-2017-11561?
A malicious user can upload a web shell by abusing the file upload functionality in the "Group Chat" or "Alarm" section of ZOHO ManageEngine OpManager.
5
Is there a fix available for CVE-2017-11561?
A fix for CVE-2017-11561 is not specified in the provided information, please refer to the vendor's website for any available patches or updates.