Authenticated Command Injection in Zoho ManageEngine Asset Explorer
CVE-2019-19034
7.2HIGH
What is CVE-2019-19034?
The Zoho ManageEngine Asset Explorer 6.5 vulnerability exposes a significant security risk by failing to properly validate the SCCM database username during the dynamic generation of scheduling commands. Attackers can exploit this oversight, leading to the execution of arbitrary commands on the Asset Explorer server with elevated privileges. This flaw poses a severe threat to the integrity and confidentiality of the affected systems, as it may allow unauthorized execution of malicious commands.