CVE-2020-13818

In Zoho ManageEngine OpManager before 125144, when <cachestart> is used, directory traversal validation can be bypassed.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
VendorProductVersion
zohocorpmanageengine_opmanager
𝑥
< 12.5
zohocorpmanageengine_opmanager
12.5
zohocorpmanageengine_opmanager
12.5:build125000
zohocorpmanageengine_opmanager
12.5:build125002
zohocorpmanageengine_opmanager
12.5:build125100
zohocorpmanageengine_opmanager
12.5:build125101
zohocorpmanageengine_opmanager
12.5:build125102
zohocorpmanageengine_opmanager
12.5:build125108
zohocorpmanageengine_opmanager
12.5:build125110
zohocorpmanageengine_opmanager
12.5:build125111
zohocorpmanageengine_opmanager
12.5:build125112
zohocorpmanageengine_opmanager
12.5:build125113
zohocorpmanageengine_opmanager
12.5:build125114
zohocorpmanageengine_opmanager
12.5:build125116
zohocorpmanageengine_opmanager
12.5:build125117
zohocorpmanageengine_opmanager
12.5:build125118
zohocorpmanageengine_opmanager
12.5:build125120
zohocorpmanageengine_opmanager
12.5:build125121
zohocorpmanageengine_opmanager
12.5:build125123
zohocorpmanageengine_opmanager
12.5:build125124
zohocorpmanageengine_opmanager
12.5:build125125
zohocorpmanageengine_opmanager
12.5:build125136
zohocorpmanageengine_opmanager
12.5:build125137
zohocorpmanageengine_opmanager
12.5:build125139
zohocorpmanageengine_opmanager
12.5:build125140
zohocorpmanageengine_opmanager
12.5:build125143
𝑥
= Vulnerable software versions