PT-2020-13701 · Zoho · Zoho Manageengine Opmanager

Yazhi Wang

·

Published

2020-06-04

·

Updated

2021-06-22

·

CVE-2020-13818

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine OpManager versions prior to 125144
Description The issue allows directory traversal validation to be bypassed when the cachestart parameter is used. This can lead to information disclosure.
Recommendations For versions prior to 125144, update to version 125144 or later to resolve the issue. As a temporary workaround, consider restricting access to the cachestart parameter to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13818
ZDI-20-691

Affected Products

Zoho Manageengine Opmanager