First published: Thu Oct 07 2021(Updated: )
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp ManageEngine ADManager Plus | <7.1 | |
Zohocorp ManageEngine ADManager Plus | =7.1 | |
Zohocorp ManageEngine ADManager Plus | =7.1-7100 | |
Zohocorp ManageEngine ADManager Plus | =7.1-7101 | |
Zohocorp ManageEngine ADManager Plus | =7.1-7102 | |
Zohocorp ManageEngine ADManager Plus | =7.1-7110 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-37928 is critical with a CVSS score of 9.8.
The affected software of CVE-2021-37928 is Zoho ManageEngine ADManager Plus version 7110 and prior.
CVE-2021-37928 is a vulnerability in Zoho ManageEngine ADManager Plus that allows unrestricted file upload, leading to remote code execution.
Yes, it is recommended to update to version 7111 or later of Zoho ManageEngine ADManager Plus to fix CVE-2021-37928.
You can find more information about CVE-2021-37928 on the Zoho ManageEngine website and the release notes for ADManager Plus.