CVE-2021-41833Unrestricted File Upload in Manageengine Patch Connect Plus

Severity
9.8CRITICALNVD
EPSS
27.3%
top 3.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 11
Latest updateMay 24

Description

Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8h8p-qpmp-fmvf: Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution2022-05-24
CVEList
CVE-2021-41833: Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution2021-11-11
CVE-2021-41833 — Unrestricted File Upload | cvebase