PT-2020-16897 · Zoho · Zoho Manageengine Applications Manager

Published

2020-10-29

·

Updated

2020-11-03

·

CVE-2020-27995

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine Applications Manager version 14 before 14560
Description The issue allows an attacker to execute commands on the server. This is achieved via the template resid parameter in the "MyPage.do" endpoint.
Recommendations For Zoho ManageEngine Applications Manager version 14 before 14560, update to version 14560 or later to resolve the issue.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-27995

Affected Products

Zoho Manageengine Applications Manager