5.5
CVE-2025-9435
- EPSS 0.54%
- Veröffentlicht 13.01.2026 13:14:03
- Zuletzt bearbeitet 29.01.2026 19:10:59
- Erkennungen
Path Traversal
Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Admanager Plus Version < 7.2
Zohocorp ≫ Manageengine Admanager Plus Version 7.2 Update 7200
Zohocorp ≫ Manageengine Admanager Plus Version 7.2 Update 7201
Zohocorp ≫ Manageengine Admanager Plus Version 7.2 Update 7202
Zohocorp ≫ Manageengine Admanager Plus Version 7.2 Update 7203
Zohocorp ≫ Manageengine Admanager Plus Version 7.2 Update 7210
Zohocorp ≫ Manageengine Admanager Plus Version 7.2 Update 7211
Zohocorp ≫ Manageengine Admanager Plus Version 7.2 Update 7212
Zohocorp ≫ Manageengine Admanager Plus Version 7.2 Update 7220
Zohocorp ≫ Manageengine Admanager Plus Version 7.2 Update 7221
Zohocorp ≫ Manageengine Admanager Plus Version 7.2 Update 7222
Zohocorp ≫ Manageengine Admanager Plus Version 7.2 Update 7223
Zohocorp ≫ Manageengine Admanager Plus Version 7.2 Update 7224
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.54% | 0.427 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 0fc0942c-577d-436f-ae8e-945763c79b02 | 5.5 | 2.1 | 3.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
|
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
https://www.manageengine.com/products/ad-manager/admanager-kb/cve-2025-9435.html