Security Advisory

CVE-2020-11531

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-05-08 20:01:36
Last updated 2024-08-04 11:35:12
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The DataEngine Xnode Server application in Zoho ManageEngine DataSecurity Plus prior to 6.0.1 does not validate the database schema name when handling a DR-SCHEMA-SYNC request. This allows an authenticated attacker to execute code in the context of the product by writing a JSP file to the webroot directory via directory traversal.