CVE-2025-10020

CWE-77Command Injection3 documents3 sources
Severity
8.8HIGH
EPSS
0.6%
top 31.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 21

Description

Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability in the Custom Script component.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 1.8 | Impact: 6.0

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
Command Injection2025-10-21
GHSA
GHSA-66pm-g8mp-38vm: Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability in the Custom Script componen2025-10-21
CVE-2025-10020 (HIGH CVSS 8.8) | Zohocorp ManageEngine ADManager Plu | cvebase.io