CVE-2018-18475Unrestricted File Upload in Manageengine Opmanager

Severity
9.8CRITICALNVD
EPSS
4.7%
top 10.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 23
Latest updateMay 13

Description

Zoho ManageEngine OpManager before 12.3 build 123214 allows Unrestricted Arbitrary File Upload.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-9f6q-g3mx-9m36: Zoho ManageEngine OpManager before 122022-05-13
CVEList
CVE-2018-18475: Zoho ManageEngine OpManager before 122018-10-23
CVE-2018-18475 — Unrestricted File Upload | cvebase