CVE-2019-15105

CVE-2019-15105

An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently upload a malicious file using the "Execute Program Action(s)" feature.

Source: CVE-2019-15105

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다