First published: Thu Aug 31 2023(Updated: )
Zoho ManageEngine ADManager Plus before 7203 allows Help Desk Technician users to read arbitrary files on the machine where this product is installed.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp ManageEngine ADManager Plus | <=7202 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39912 is a vulnerability in Zoho ManageEngine ADManager Plus through version 7202 that allows admin users to download any file from the server machine via directory traversal.
This vulnerability can be exploited by admin users to download any file from the server machine through directory traversal.
CVE-2023-39912 has a severity level of medium with a severity value of 4.9.
The vendor has released a patch to fix this vulnerability. It is recommended to update Zoho ManageEngine ADManager Plus to version 7203 or higher to mitigate the risk.
More information about CVE-2023-39912 can be found on the official website of Zoho ManageEngine as well as in the provided reference links.