OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HZohocorp Manageengine Supportcenter Plus
APPZohocorp11.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
Related vulnerabilities
CVE-2022-47966CRITICAL9.8⚠ KEVPL ✓same product
RCE w wielu produktach Zoho ManageEngine przez podatną bibliotekę Apache Santuario xmlsec
CVE-2021-44077CRITICAL9.8⚠ KEVPL ✓same product
Nieuwierzytelniony RCE w Zoho ManageEngine ServiceDesk Plus
CVE-2022-36412CRITICAL9.8PL ✓same product
Pominięcie uwierzytelnienia w Zoho ManageEngine SupportCenter Plus — V3 API
CVE-2024-38869HIGH8.3same product
Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office depl...
CVE-2023-35785HIGH8.1same product
Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 72...