CVE-2023-39912

MEDIUM

ManageEngine ADManager Plus < 7203 - Authenticated Arbitrary File Read via Help Desk Technician Role

Title source: llm
STIX 2.1

Description

Zoho ManageEngine ADManager Plus before 7203 allows Help Desk Technician users to read arbitrary files on the machine where this product is installed.

Scores

CVSS v3 4.9
EPSS 0.0101
EPSS Percentile 77.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
zohocorp/manageengine_admanager_plus 7.2 7200 (3 CPE variants)
zohocorp/manageengine_admanager_plus < 7.2
Published Aug 31, 2023
Tracked Since Feb 18, 2026