TROYANOSYVIRUS
Retour aux CVEs

CVE-2018-17283

N/A

Description

Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServlet?action=getAPIKey request that can be leveraged against Firewall Analyzer to add an admin user via /api/json/v2/admin/addUser or conduct a SQL Injection attack via the /api/json/device/setManaged name parameter.

Details CVE

Score CVSS v3.1N/A
Publie9/21/2018
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0

Produits affectes

zohocorp:manageengine_opmanager

Faiblesses (CWE)

CWE-89

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.