CVE-2014-0344
Properties.do in ZOHO ManageEngine OpStor before build 8500 does not properly check privilege levels, which allows remote authenticated users to obtain Admin access by using the name parameter in conjunction with a true value of the edit parameter.
Ver en NVDSeveridad
N/A
EPSS
Probabilidad de explotación (próx. 30 días): 0.0128 (1.3%)
Percentil: 79.7%
EPSS: 2026-05-06
Afecta
zohocorp:manageengine_opstorDescripción técnica
Properties.do in ZOHO ManageEngine OpStor before build 8500 does not properly check privilege levels, which allows remote authenticated users to obtain Admin access by using the name parameter in conjunction with a true value of the edit parameter.
Publicada: 29/3/2014, 20:55:04
Última modificación: 6/5/2026, 22:30:45