CVE-2021-41833: Malicious File Upload
Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-41833?
The severity of CVE-2021-41833 is critical.
How does CVE-2021-41833 affect Zoho ManageEngine Patch Connect Plus?
CVE-2021-41833 allows unauthenticated remote code execution in Zoho ManageEngine Patch Connect Plus version 9.0.0.
How can I fix CVE-2021-41833?
To fix CVE-2021-41833, you should update Zoho ManageEngine Patch Connect Plus to version 9.0.0-build90099 or higher.
What is the Common Weakness Enumeration (CWE) ID of CVE-2021-41833?
The Common Weakness Enumeration (CWE) ID of CVE-2021-41833 is 434.
Where can I find more information about CVE-2021-41833?
You can find more information about CVE-2021-41833 at the following references: [Reference 1](https://pitstop.manageengine.com/portal/en/community/topic/unauthenticated-remote-code-execution-vulnerability-solved) and [Reference 2](https://www.manageengine.com/sccm-third-party-patch-management/kb/unauthenticated-remote-code-execution.html).