CVE-2021-42002

CRITICAL

Zoho ManageEngine ADManager Plus < 7115 - Remote Code Execution via File Upload Filter Bypass

Title source: llm
STIX 2.1

Description

Zoho ManageEngine ADManager Plus before 7115 is vulnerable to a filter bypass that leads to file-upload remote code execution.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0927
EPSS Percentile 92.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (2)
zohocorp/manageengine_admanager_plus 7.1 (9 CPE variants)
zohocorp/manageengine_admanager_plus < 7.1
Published Nov 11, 2021
Tracked Since Feb 18, 2026