Record summary

CVE-2020-12116 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read arbitrary files on the server by sending a crafted request.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

Proofs of concept

1

Repository PoCs

GitHubBeetleChunks/CVE-2020-12116Repository PoCby BeetleChunksStars: 30Not analyzed2 files

8.7 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHZoho ManageEngine OpManger - Arbitrary File ReadCVSS 7.5

Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read arbitrary files on the server by sending a specially crafted request.

Impact

An attacker can read sensitive files on the server, potentially leading to unauthorized access, data leakage, or further exploitation.

Remediation

Apply the latest security patch or upgrade to a patched version of Zoho ManageEngine OpManger to mitigate the vulnerability.

WeaknessesCWE-22
Authorsdwisiswant0
Template tagscvecve2020zoholfimanageenginezohocorpvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:zohocorp:manageengine_opmanager:*:*:*:*:*:*:*:*
Shodan: http.title:"opmanager plus"
FOFA: title="opmanager plus"
Google: intitle:"opmanager plus"

Source: ProjectDiscovery

References

2