CVE-2020-21642: Path Traversal
Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attackers to run arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the Directory Traversal vulnerability in Zoho ManageEngine Analytics Plus?
The vulnerability ID for the Directory Traversal vulnerability in Zoho ManageEngine Analytics Plus is CVE-2020-21642.
What is the severity of CVE-2020-21642?
The severity of CVE-2020-21642 is critical with a CVSS score of 9.8.
Which software versions are affected by CVE-2020-21642?
The affected software versions for CVE-2020-21642 are Zoho ManageEngine Analytics Plus 2.9-build2900 to 4.3-build4310.
How can remote attackers exploit CVE-2020-21642?
Remote attackers can exploit CVE-2020-21642 by using a specially crafted request to the ZDBQAREFSUBDIR parameter in the /zropusermgmt API to perform directory traversal and run arbitrary code.
Where can I find more information about CVE-2020-21642?
You can find more information about CVE-2020-21642 in the release notes of Zoho ManageEngine Analytics Plus.