PT-2015-6784 · Zoho · Zoho Manageengine Supportcenter Plus
Alain Homewood
·
Published
2015-06-30
·
Updated
2016-12-07
·
CVE-2015-5149
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Zoho ManageEngine SupportCenter Plus version 7.90
Description
A directory traversal issue exists, allowing remote authenticated users to write to arbitrary files. This is achieved by including a .. (dot dot) in the
component parameter in the Request component to "workorder/Attachment.jsp" API endpoint.Recommendations
For Zoho ManageEngine SupportCenter Plus version 7.90, consider restricting access to the "workorder/Attachment.jsp" endpoint until a patch is available. As a temporary workaround, avoid using the
component parameter in the Request component to minimize the risk of exploitation.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zoho Manageengine Supportcenter Plus