CVE-2014-0344
Last modified
CVE-2014-0344 is a vulnerability of currently unknown severity. Properties.do in ZOHO ManageEngine OpStor before build 8500 does not properly check privilege levels, which allows remote authenticated users to obtain Admin access by using the name parameter in conjunction with a true value of the edit parameter.. EPSS estimates a 5.53% chance of exploitation in the next 30 days.
Description
Properties.do in ZOHO ManageEngine OpStor before build 8500 does not properly check privilege levels, which allows remote authenticated users to obtain Admin access by using the name parameter in conjunction with a true value of the edit parameter.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zohocorp | Manageengine Opstor | <= 8.3 |
References
- http://www.kb.cert.org/vuls/id/140886Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/140886Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-0344?
How severe is CVE-2014-0344?
How do I fix CVE-2014-0344?
Are you affected by CVE-2014-0344?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
