CVE-2021-28959

CWE-22Path Traversal3 documents3 sources
Severity
9.8CRITICAL
EPSS
24.1%
top 3.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 30
Latest updateMay 24

Description

Zoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a ZIP archive. This leads to remote code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-jqhq-x433-j3xh: Zoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a ZIP archive2022-05-24
CVEList
CVE-2021-28959: Zoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a ZIP archive2021-04-30
CVE-2021-28959 (CRITICAL CVSS 9.8) | Zoho ManageEngine Eventlog Analyzer | cvebase.io