CVE-2019-8925
MEDIUMZohocorp Manageengine Netflow Analyzer - Path Traversal
Title source: ruleDescription
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. An Absolute Path Traversal vulnerability in the Administration zone, in /netflow/servlet/CReportPDFServlet (via the parameter schFilePath), allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via any file name, such as a schFilePath=C:\boot.ini value.
Exploits (1)
References (4)
Scores
CVSS v3
4.3
EPSS
0.0902
EPSS Percentile
92.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-22
Status
published
Products (1)
zohocorp/manageengine_netflow_analyzer
7.0.0.2
Published
May 17, 2019
Tracked Since
Feb 18, 2026