Privilege Escalation Vulnerability in ZOHO ManageEngine OpStor
CVE-2014-0344

Currently unrated

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
29 March 2014

What is CVE-2014-0344?

In ZOHO ManageEngine OpStor prior to build 8500, the Properties.do component fails to adequately enforce access controls. This oversight enables remote authenticated users to exploit the name parameter in conjunction with a true value of the edit parameter, potentially granting them unauthorized administrative access to the system. This vulnerability puts user accounts and sensitive data at risk, necessitating immediate attention for users operating the affected versions.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.