CVE-2023-47211
ManageEngine OpManager - Directory Traversal
Record summary
CVE-2023-47211 has a selected CVSS score of 9.1 (critical); EIP currently links 1 Nuclei template.
Description
A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated May 8, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
OpManagerBrowse ManageEngine / OpManager | CVE List | 12.7.258 | affected |
Nuclei templates
1ProjectDiscoveryHIGHManageEngine OpManager - Directory TraversalCVSS 8.6
A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability.
Impact
Unauthenticated attackers can write arbitrary files to the system via path traversal, potentially creating backdoors or compromising system integrity.
Remediation
Update ManageEngine OpManager to version 12.7.259 or later.
Source: ProjectDiscovery