CVE-2018-11808

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
06/06/2018
Last modified:
07/08/2018

Description

Incorrect Access Control in CustomFieldsFeedServlet in Zoho ManageEngine Applications Manager Version 13 before build 13740 allows an attacker to delete any file and read certain files on the server in the context of the user (which by default is "NT AUTHORITY / SYSTEM") by sending a specially crafted request to the server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zohocorp:manageengine_applications_manager:13:*:*:*:*:*:*:*