5.5
CVE-2025-9435
- EPSS 0.52%
- Veröffentlicht 13.01.2026 13:14:03
- Zuletzt bearbeitet 29.01.2026 19:10:59
- Quelle 0fc0942c-577d-436f-ae8e-945763
- CVE-Watchlists
- Unerledigt
Path Traversal
Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Admanager Plus Version < 7.2
Zohocorp ≫ Manageengine Admanager Plus Version7.2 Update7200
Zohocorp ≫ Manageengine Admanager Plus Version7.2 Update7201
Zohocorp ≫ Manageengine Admanager Plus Version7.2 Update7202
Zohocorp ≫ Manageengine Admanager Plus Version7.2 Update7203
Zohocorp ≫ Manageengine Admanager Plus Version7.2 Update7210
Zohocorp ≫ Manageengine Admanager Plus Version7.2 Update7211
Zohocorp ≫ Manageengine Admanager Plus Version7.2 Update7212
Zohocorp ≫ Manageengine Admanager Plus Version7.2 Update7220
Zohocorp ≫ Manageengine Admanager Plus Version7.2 Update7221
Zohocorp ≫ Manageengine Admanager Plus Version7.2 Update7222
Zohocorp ≫ Manageengine Admanager Plus Version7.2 Update7223
Zohocorp ≫ Manageengine Admanager Plus Version7.2 Update7224
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.52% | 0.4 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 0fc0942c-577d-436f-ae8e-945763c79b02 | 5.5 | 2.1 | 3.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
|
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
https://www.manageengine.com/products/ad-manager/admanager-kb/cve-2025-9435.html