ZeroHour

CVE-2017-11561

PoC
CVSS 3.0
6.5 medium
EPSS
2%p80
Published
()
Modified
Description

An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Alarm" section. This functionality can be abused by a malicious user by uploading a web shell.

Vendors
zohocorp
Products
manageengine opmanager
Weakness
CWE-434
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.