CVE-2021-37923

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
VendorProductVersion
zohocorpmanageengine_admanager_plus
𝑥
< 7.1
zohocorpmanageengine_admanager_plus
7.1
zohocorpmanageengine_admanager_plus
7.1:7100
zohocorpmanageengine_admanager_plus
7.1:7101
zohocorpmanageengine_admanager_plus
7.1:7102
zohocorpmanageengine_admanager_plus
7.1:7110
𝑥
= Vulnerable software versions