CVE-2023-39912

Zoho ManageEngine ADManager Plus before 7203 allows Help Desk Technician users to read arbitrary files on the machine where this product is installed.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zohocorp:manageengine_admanager_plus:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:16

Type Values Removed Values Added
References () https://manageengine.com - Product () https://manageengine.com - Product
References () https://www.manageengine.com/products/ad-manager/admanager-kb/cve-2023-39912.html - Vendor Advisory () https://www.manageengine.com/products/ad-manager/admanager-kb/cve-2023-39912.html - Vendor Advisory

01 Jan 2024, 06:15

Type Values Removed Values Added
Summary (en) Zoho ManageEngine ADManager Plus through 7202 allows admin users to download any file from the server machine via directory traversal. (en) Zoho ManageEngine ADManager Plus before 7203 allows Help Desk Technician users to read arbitrary files on the machine where this product is installed.

Information

Published : 2023-08-31 23:15

Updated : 2024-11-21 08:16


NVD link : CVE-2023-39912

Mitre link : CVE-2023-39912

CVE.ORG link : CVE-2023-39912


JSON object : View

Products Affected

zohocorp

  • manageengine_admanager_plus
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')