PT-2024-1428 · Zoho · Zoho Manageengine Adaudit Plus

Published

2024-01-24

·

Updated

2024-10-28

·

CVE-2023-50785

CVSS v2.0

3.3

Low

VectorAV:N/AC:L/Au:M/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine ADAudit Plus versions prior to 7270
Description The issue is related to incorrect restriction of directory path names with limited access, allowing admin users to view names of arbitrary directories via path traversal. This could enable a remote attacker to gain unauthorized access to confidential information.
Recommendations For versions prior to 7270, update to version 7270 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive directories to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-00903
CVE-2023-50785

Affected Products

Zoho Manageengine Adaudit Plus