Direct Inward Dialing: +1 408 916 9393
| Vulnerability details | |
| Severity | Medium |
| CVE ID | CVE-2025-9435 |
| Affected software versions | 7224 and older |
| Fixed version | 7230 |
| Fixed on | March 06, 2024 |
CVE-2025-9435 refers to a security vulnerability in the User Management module of ADManager Plus where authenticated users could create arbitrary folders on the ADManager Plus server instance and gain access to that particular folder and inject files. This issue has been fixed in build 7230, and the release notes can be found here.
This vulnerability could allow an authenticated adversary to create arbitrary folders on the ADManager Plus server instance.
Update your ADManager Plus instance to its latest build by installing the service pack.
This vulnerability was reported by metin kandemir via Zoho's Bug Bounty program.
Select a language to translate the contents of this web page:
Fill this form, and we'll contact you rightaway.
Our technical support team will get in touch with you at the earliest."