CVE-2021-20131: Malicious File Upload
Published Oct 13, 2021
·Updated
ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the Personalization interface.
Affected Software
6 affected components
ZohoCorp ManageEngine ADManager Plus<7.1
ZohoCorp ManageEngine ADManager Plus=7.1
ZohoCorp ManageEngine ADManager Plus=7.1-7100
ZohoCorp ManageEngine ADManager Plus=7.1-7101
ZohoCorp ManageEngine ADManager Plus=7.1-7102
ZohoCorp ManageEngine ADManager Plus=7.1-7110
Event History
Oct 13, 2021
CVE Published
via MITRE·05:30 PM
Data Sourced
via MITRE·05:30 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-20131?
CVE-2021-20131 is a vulnerability that allows for remote code execution in ManageEngine ADManager Plus Build 7111.
2
How severe is CVE-2021-20131?
CVE-2021-20131 has a severity rating of 8.8, which is considered high.
3
How does CVE-2021-20131 occur?
CVE-2021-20131 occurs due to improperly validated file uploads in the Personalization interface of ManageEngine ADManager Plus Build 7111.
4
Which software versions are affected by CVE-2021-20131?
ManageEngine ADManager Plus versions 7.1, 7.1-7100, 7.1-7101, 7.1-7102, and 7.1-7110 are affected by CVE-2021-20131.
5
Is there a fix for CVE-2021-20131?
Patch/update to a fixed version of ManageEngine ADManager Plus, such as version 7111, to fix CVE-2021-20131.