CVE-2025-10020

Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability in the Custom Script component.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.5 HIGH
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
ZohocorpCNA
8.5 HIGH
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 73%
VendorProductVersion
zohocorpmanageengine_admanager_plus
𝑥
< 8.0
zohocorpmanageengine_admanager_plus
8.0:8001
zohocorpmanageengine_admanager_plus
8.0:8002
zohocorpmanageengine_admanager_plus
8.0:8010
zohocorpmanageengine_admanager_plus
8.0:8011
zohocorpmanageengine_admanager_plus
8.0:8012
zohocorpmanageengine_admanager_plus
8.0:8020
zohocorpmanageengine_admanager_plus
8.0:8021
zohocorpmanageengine_admanager_plus
8.0:8022
zohocorpmanageengine_admanager_plus
8.0:8023
𝑥
= Vulnerable software versions