peter bassill · operator
$ cve CVE-2019-11469 JSON

CVE-2019-11469 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 17% (pctl 97)

Patch early

A public exploit exists.

Description

Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user can gain the authority of SYSTEM on the server by uploading a malicious file via the "Execute Program Action(s)" feature.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS16.97% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2019-04-23
Last modified2026-06-17

Affected (1)

VendorProduct
zohocorpmanageengine applications manager

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD