ZeroHour

CVE-2023-47211

PoC
CVSS 3.1
8.6 high
EPSS
47%p99
Published
()
Modified
Description

A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability.

Vendors
zohocorp
Products
manageengine firewall analyzer, manageengine netflow analyzer, manageengine network configuration manager, manageengine opmanager, manageengine opmanager msp, manageengine opmanager plus, manageengine oputils
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

In the news