Untrusted search path in ManageEngine Applications Manager - CVE-2022-23050
Published: February 16, 2022
ManageEngine Applications Manager
Detailed vulnerability description
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to the application tries to load DLL files and scripts from the current working directory. A remote user can upload a malicious DLL via the 'Upload Files / Binaries' functionality and execute it on the system after service restart.