CVE-2021-37928: Malicious File Upload
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict or block access to the ADManager Plus file upload functionality (the vulnerable upload feature that allows unrestricted file uploads leading to remote code execution) using network controls (firewall/ACL/WAF) until the application is upgraded.
Event History
Frequently Asked Questions
What is the severity of CVE-2021-37928?
The severity of CVE-2021-37928 is critical with a CVSS score of 9.8.
What is the affected software of CVE-2021-37928?
The affected software of CVE-2021-37928 is Zoho ManageEngine ADManager Plus version 7110 and prior.
What is the vulnerability description of CVE-2021-37928?
CVE-2021-37928 is a vulnerability in Zoho ManageEngine ADManager Plus that allows unrestricted file upload, leading to remote code execution.
Is there a fix available for CVE-2021-37928?
Yes, it is recommended to update to version 7111 or later of Zoho ManageEngine ADManager Plus to fix CVE-2021-37928.
Where can I find more information about CVE-2021-37928?
You can find more information about CVE-2021-37928 on the Zoho ManageEngine website and the release notes for ADManager Plus.