CVE-2022-41339 — Improper Privilege Management in Manageengine Mobile Device Manager Plus

Severity
7.8HIGHNVD
EPSS
0.0%
top 86.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 12

Description

In Zoho ManageEngine Mobile Device Manager Plus before 10.1.2207.5, the User Administration module allows privilege escalation.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-534h-8p2m-59rg: In Zoho ManageEngine Mobile Device Manager Plus before 10↗2022-11-12
â–¶
CVEList
CVE-2022-41339: In Zoho ManageEngine Mobile Device Manager Plus before 10↗2022-11-12
â–¶
CVE-2022-41339 — Improper Privilege Management | cvebase