CVE-2020-12116
Zoho ManageEngine OpManger - Arbitrary File Read
Record summary
CVE-2020-12116 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read arbitrary files on the server by sending a crafted request.
Exploitation context
Proofs of concept
1Repository PoCs
GitHubBeetleChunks/CVE-2020-12116Repository PoCby BeetleChunksStars: 30Not analyzed2 files
Nuclei templates
1ProjectDiscoveryHIGHZoho ManageEngine OpManger - Arbitrary File ReadCVSS 7.5
Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read arbitrary files on the server by sending a specially crafted request.
Impact
An attacker can read sensitive files on the server, potentially leading to unauthorized access, data leakage, or further exploitation.
Remediation
Apply the latest security patch or upgrade to a patched version of Zoho ManageEngine OpManger to mitigate the vulnerability.
Source: ProjectDiscovery