ManageEngine ADManager Plus
cpe:2.3:a:zohocorp:manageengine_admanager_plus:*:*:*:*:*:*:*
- <= 7224
A path traversal vulnerability has been identified in ManageEngine ADManager Plus, affecting versions prior to 7230. This vulnerability allows authenticated users to create arbitrary folders on the ADManager Plus server and inject files into those folders. The issue has been addressed in version 7230, released on March 6, 2024.
Exploitation of this vulnerability could enable an authenticated user to create arbitrary directories on the ADManager Plus server and inject files into those directories.
Users can update their ADManager Plus instance to the latest build by installing the available service pack.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.