CVE-2018-11808

CRITICAL

Zoho ManageEngine Apps Mgr <13-13740 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Incorrect Access Control in CustomFieldsFeedServlet in Zoho ManageEngine Applications Manager Version 13 before build 13740 allows an attacker to delete any file and read certain files on the server in the context of the user (which by default is "NT AUTHORITY / SYSTEM") by sending a specially crafted request to the server.

References (4)

Core 4
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://www.manageengine.com/products/applications_manager/issues.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/104467

Scores

CVSS v3 9.1
EPSS 0.0423
EPSS Percentile 88.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-20
Status published
Products (1)
zohocorp/manageengine_applications_manager 13
Published Jun 06, 2018
Tracked Since Feb 18, 2026