CVE-2018-18980: Zohocorp ManageEngine Network Configuration Manager

High severity, CVSS 7.5. EPSS: 25% chance of exploitation in the next 30 days.

An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the RequestXML parameter in a /devices/ProcessRequest.do GET request. For example, the attacker can trigger the transmission of local files to an arbitrary remote FTP server.

Affected products

  • Zohocorp ManageEngine Network Configuration Manager: before 12.3.214 (fixed in 12.3.214)
  • Zohocorp ManageEngine Opmanager: before 12.3.214 (fixed in 12.3.214)

Published 2018-11-06. Last modified 2026-06-17.