nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-38743 CVE-2023-38743
HIGH
Zoho ManageEngine ADManager Plus Authenticated Vulnerability
Record summary
CVE-2023-38743 has a selected CVSS score of 7.2 (high); EIP currently links 1 repository PoC.
Description
Zoho ManageEngine ADManager Plus before Build 7200 allows admin users to execute commands on the host machine.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 1, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
manageengine_admanager_plusBrowse Zoho / manageengine_admanager_plus | VulnCheck | Version data not supplied | |
Proofs of concept
1Repository PoCs
GitHubPetrusViet/CVE-2023-38743Repository PoCby PetrusVietStars: 11Not analyzed2 files
References
2manageengine.com
https://www.manageengine.com/products/ad-manager/admanager-kb/cve-2023-38743.html