Authorization Issue in Zoho ManageEngine Remote Access Plus
CVE-2019-20474
4.3MEDIUM
What is CVE-2019-20474?
An authorization flaw exists in Zoho ManageEngine Remote Access Plus version 10.0.447, where a user with 'Guest' role privileges is granted access to exploit the mail-server configuration testing service. This vulnerability permits unauthorized operations, such as conducting network and port scans on localhost or devices within the same network segment, thereby facilitating Server Side Request Forgery (SSRF) attacks.
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved