Vulnerabilities > Zohocorp > Manageengine Admanager Plus > 6610

DATE CVE VULNERABILITY TITLE RISK
2023-08-31 CVE-2023-39912 Path Traversal vulnerability in Zohocorp Manageengine Admanager Plus
Zoho ManageEngine ADManager Plus before 7203 allows Help Desk Technician users to read arbitrary files on the machine where this product is installed.
network
low complexity
zohocorp CWE-22
4.9
2018-02-07 CVE-2017-17552 Cross-Site Request Forgery (CSRF) vulnerability in Zohocorp Manageengine Admanager Plus
/LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resulting in a bypass of CSRF protection, or potentially masquerading a malicious URL as trusted.
network
low complexity
zohocorp CWE-352
8.8