CWE
434
Advisory Published
Updated

CVE-2021-41833: Malicious File Upload

First published: Thu Nov 11 2021(Updated: )

Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution.

Credit: cve@mitre.org cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Zoho ManageEngine Patch Connect Plus<9.0.0
Zoho ManageEngine Patch Connect Plus=9.0.0
Zoho ManageEngine Patch Connect Plus=9.0.0-build90001
Zoho ManageEngine Patch Connect Plus=9.0.0-build90063
Zoho ManageEngine Patch Connect Plus=9.0.0-build90064
Zoho ManageEngine Patch Connect Plus=9.0.0-build90065
Zoho ManageEngine Patch Connect Plus=9.0.0-build90066
Zoho ManageEngine Patch Connect Plus=9.0.0-build90067
Zoho ManageEngine Patch Connect Plus=9.0.0-build90068
Zoho ManageEngine Patch Connect Plus=9.0.0-build90069
Zoho ManageEngine Patch Connect Plus=9.0.0-build90070
Zoho ManageEngine Patch Connect Plus=9.0.0-build90071
Zoho ManageEngine Patch Connect Plus=9.0.0-build90072
Zoho ManageEngine Patch Connect Plus=9.0.0-build90073
Zoho ManageEngine Patch Connect Plus=9.0.0-build90074
Zoho ManageEngine Patch Connect Plus=9.0.0-build90075
Zoho ManageEngine Patch Connect Plus=9.0.0-build90076
Zoho ManageEngine Patch Connect Plus=9.0.0-build90077
Zoho ManageEngine Patch Connect Plus=9.0.0-build90078
Zoho ManageEngine Patch Connect Plus=9.0.0-build90079
Zoho ManageEngine Patch Connect Plus=9.0.0-build90080
Zoho ManageEngine Patch Connect Plus=9.0.0-build90081
Zoho ManageEngine Patch Connect Plus=9.0.0-build90082
Zoho ManageEngine Patch Connect Plus=9.0.0-build90083
Zoho ManageEngine Patch Connect Plus=9.0.0-build90084
Zoho ManageEngine Patch Connect Plus=9.0.0-build90085
Zoho ManageEngine Patch Connect Plus=9.0.0-build90086
Zoho ManageEngine Patch Connect Plus=9.0.0-build90087
Zoho ManageEngine Patch Connect Plus=9.0.0-build90088
Zoho ManageEngine Patch Connect Plus=9.0.0-build90089
Zoho ManageEngine Patch Connect Plus=9.0.0-build90090
Zoho ManageEngine Patch Connect Plus=9.0.0-build90091
Zoho ManageEngine Patch Connect Plus=9.0.0-build90092
Zoho ManageEngine Patch Connect Plus=9.0.0-build90093
Zoho ManageEngine Patch Connect Plus=9.0.0-build90094
Zoho ManageEngine Patch Connect Plus=9.0.0-build90095
Zoho ManageEngine Patch Connect Plus=9.0.0-build90096
Zoho ManageEngine Patch Connect Plus=9.0.0-build90097
Zoho ManageEngine Patch Connect Plus=9.0.0-build90098

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2021-41833?

    The severity of CVE-2021-41833 is critical.

  • How does CVE-2021-41833 affect Zoho ManageEngine Patch Connect Plus?

    CVE-2021-41833 allows unauthenticated remote code execution in Zoho ManageEngine Patch Connect Plus version 9.0.0.

  • How can I fix CVE-2021-41833?

    To fix CVE-2021-41833, you should update Zoho ManageEngine Patch Connect Plus to version 9.0.0-build90099 or higher.

  • What is the Common Weakness Enumeration (CWE) ID of CVE-2021-41833?

    The Common Weakness Enumeration (CWE) ID of CVE-2021-41833 is 434.

  • Where can I find more information about CVE-2021-41833?

    You can find more information about CVE-2021-41833 at the following references: [Reference 1](https://pitstop.manageengine.com/portal/en/community/topic/unauthenticated-remote-code-execution-vulnerability-solved) and [Reference 2](https://www.manageengine.com/sccm-third-party-patch-management/kb/unauthenticated-remote-code-execution.html).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203