Files
CVEs-PoC/2020/CVE-2020-11531.md
T
2024-06-18 02:51:15 +02:00

913 B

CVE-2020-11531

Description

The DataEngine Xnode Server application in Zoho ManageEngine DataSecurity Plus prior to 6.0.1 does not validate the database schema name when handling a DR-SCHEMA-SYNC request. This allows an authenticated attacker to execute code in the context of the product by writing a JSP file to the webroot directory via directory traversal.

POC

Reference

Github

No PoCs found on GitHub currently.