First published: Sat Nov 12 2022(Updated: )
In Zoho ManageEngine Mobile Device Manager Plus before 10.1.2207.5, the User Administration module allows privilege escalation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Mobile Device Manager Plus | =10.1.2207.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-41339 is a vulnerability in Zoho ManageEngine Mobile Device Manager Plus before version 10.1.2207.5 that allows privilege escalation through the User Administration module.
CVE-2022-41339 has a severity rating of 7.8 (high).
The affected software version of CVE-2022-41339 is Zoho ManageEngine Mobile Device Manager Plus 10.1.2207.4.
To fix CVE-2022-41339, update your Zoho ManageEngine Mobile Device Manager Plus installation to version 10.1.2207.5 or later.
You can find more information about CVE-2022-41339 on the Zoho ManageEngine Mobile Device Manager Plus knowledge base page: https://www.manageengine.com/mobile-device-management/kb/CVE-2022-41339.html