Zoho ManageEngine Remote Access Plus 10.0.258 does not validate user permissions properly, allowing for privilege escalation and eventually a full application takeover.
References
Link | Resource |
---|---|
https://www.manageengine.com/remote-desktop-management/knowledge-base/elevation-of-privilege.html | Vendor Advisory |
Configurations
Information
Published : 2020-03-19 10:15
Updated : 2020-08-24 10:37
NVD link : CVE-2019-11361
Mitre link : CVE-2019-11361
JSON object : View
CWE
CWE-863
Incorrect Authorization
Products Affected
zohocorp
- manageengine_remote_access_plus