#VU51384 Path traversal in Zoho ManageEngine OpManager - CVE-2021-20078
Published: March 10, 2021 / Updated: April 1, 2021
Zoho ManageEngine OpManager
Zoho Corporation
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in the Spark Gateway component. A remote attacker can send a specially crafted HTTP request and delete arbitrary files on the system.