CVE-2020-11527

Remote Code Execution (RCE) vulnerability in Mail Server Settings v1 APIs

 

Vulnerability Details
ImpactCVSS V3 rating: NA
Reported14th January 2020
Reported byjacky.xing@dbappsecurity.com.cn
Fixed28th January 2020
Affected BuildsBuilds till 124180
Fixed inBuild 124181
OverviewFile read vulnerability in Arbitrary file
Recommended FixUpgrade to OpUtils Version 12.4.181 or above.

 

Description

Previously, the users were able to read the Arbitrary file, which made it vulnerable. This file read vulnerability has been fixed.

We recommend that you upgrade to OpUtils version 12.4.181 or above or contact our support team at oputils-support@manageengine.com to fix this issue.

Source and Acknowledgements

Find out more about CVE-2020-11527 from the CVE dictionary.

Need Help?

For clarification or corrections please contact our support team or email us at oputils-support@manageengine.com