CVE-2025-9435
MEDIUMZohocorp ManageEngine ADManager Plus <7230 - Path Traversal
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-9435. PoCs published by passtheticket.
AI-analyzed exploit summary This repository provides a detailed technical writeup for CVE-2025-9435, an elevation of privilege vulnerability in ADManager Plus Build < 7230. It describes how a technician user with specific permissions can exploit arbitrary directory creation to execute a malicious DLL with elevated privileges.
Description
Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module
Exploits (1)
This repository provides a detailed technical writeup for CVE-2025-9435, an elevation of privilege vulnerability in ADManager Plus Build < 7230. It describes how a technician user with specific permissions can exploit arbitrary directory creation to execute a malicious DLL with elevated privileges.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L