PT-2022-25817 · Zoho · Zoho Manageengine Mobile Device Manager Plus

Sahil Dhar

·

Published

2022-11-12

·

Updated

2022-11-16

·

CVE-2022-41339

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine Mobile Device Manager Plus versions prior to 10.1.2207.5
Description The issue allows privilege escalation through the User Administration module.
Recommendations For versions prior to 10.1.2207.5, update to version 10.1.2207.5 or later to resolve the issue.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2022-41339

Affected Products

Zoho Manageengine Mobile Device Manager Plus