CVE-2021-37918: Malicious File Upload
Published Oct 7, 2021
·Updated
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
Affected Software
6 affected components
ZohoCorp ManageEngine ADManager Plus<7.1
ZohoCorp ManageEngine ADManager Plus=7.1
ZohoCorp ManageEngine ADManager Plus=7.1-7100
ZohoCorp ManageEngine ADManager Plus=7.1-7101
ZohoCorp ManageEngine ADManager Plus=7.1-7102
ZohoCorp ManageEngine ADManager Plus=7.1-7110
Event History
Oct 7, 2021
CVE Published
via MITRE·03:33 PM
Data Sourced
via MITRE·03:33 PM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-37918?
CVE-2021-37918 is a vulnerability in Zoho ManageEngine ADManager Plus version 7110 and prior that allows unrestricted file upload, leading to remote code execution.
2
How severe is CVE-2021-37918?
CVE-2021-37918 has a severity rating of 9.8 (critical) on the CVSS scale.
3
How does CVE-2021-37918 affect Zoho ManageEngine ADManager Plus?
CVE-2021-37918 affects Zoho ManageEngine ADManager Plus versions 7110 and prior.
4
What is the recommended solution for CVE-2021-37918?
To mitigate the vulnerability, it is recommended to update Zoho ManageEngine ADManager Plus to version 7.1-7111 or higher.
5
Where can I find more information about CVE-2021-37918?
You can find more information about CVE-2021-37918 on the ManageEngine website and the ADManager Plus release notes.