CVE-2020-11531
Last modified
CVE-2020-11531 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The DataEngine Xnode Server application in Zoho ManageEngine DataSecurity Plus prior to 6.0.1 does not validate the database schema name when handling a DR-SCHEMA-SYNC request. This allows an authenticated attacker to execute code in the context of the product by writing a JSP file to the webroot directory via directory traversal.. EPSS estimates a 13.66% chance of exploitation in the next 30 days.
Description
The DataEngine Xnode Server application in Zoho ManageEngine DataSecurity Plus prior to 6.0.1 does not validate the database schema name when handling a DR-SCHEMA-SYNC request. This allows an authenticated attacker to execute code in the context of the product by writing a JSP file to the webroot directory via directory traversal.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zohocorp | Manageengine Adaudit Plus | < 6.0.1 |
| Zohocorp | Manageengine Datasecurity Plus | < 6.0.1 |
References
- http://packetstormsecurity.com/files/157604/ManageEngine-DataSecurity-Plus-Path-Traversal-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2020/May/27Exploit, Mailing List, Third Party Advisory
- http://packetstormsecurity.com/files/157604/ManageEngine-DataSecurity-Plus-Path-Traversal-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2020/May/27Exploit, Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-11531?
How severe is CVE-2020-11531?
How do I fix CVE-2020-11531?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-11526libfreerdp/core/update.c in FreeRDP versions > 1.1 through 2…2.2
- CVE-2020-11527In Zoho ManageEngine OpManager before 12.4.181, an unauthent…7.5
- CVE-2020-11528bit2spr 1992-06-07 has a stack-based buffer overflow (129-by…7.5
- CVE-2020-11529Common/Grav.php in Grav before 1.7 has an Open Redirect. Thi…6.1
- CVE-2020-1153A remote code execution vulnerability exists in the way that…7.8
- CVE-2020-11530A blind SQL injection vulnerability is present in Chop Slide…9.8
- CVE-2020-11532Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses defa…9.8
- CVE-2020-11533Ivanti Workspace Control before 10.4.30.0, when SCCM integra…5.5
- CVE-2020-11534An issue was discovered in ONLYOFFICE Document Server 5.5.0.…9.8
- CVE-2020-11535An issue was discovered in ONLYOFFICE Document Server 5.5.0.…9.8
- CVE-2020-11536An issue was discovered in ONLYOFFICE Document Server 5.5.0.…9.8
- CVE-2020-11537A SQL Injection issue was discovered in ONLYOFFICE Document …9.8
Are you affected by CVE-2020-11531?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
