First published: Thu May 23 2019(Updated: )
An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Alarm" section. This functionality can be abused by a malicious user by uploading a web shell.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp ManageEngine OpManager | =12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2017-11561.
The severity of CVE-2017-11561 is medium with a severity value of 6.5.
ZOHO ManageEngine OpManager version 12.2 is affected by CVE-2017-11561.
A malicious user can upload a web shell by abusing the file upload functionality in the "Group Chat" or "Alarm" section of ZOHO ManageEngine OpManager.
A fix for CVE-2017-11561 is not specified in the provided information, please refer to the vendor's website for any available patches or updates.