CVE-2020-21642: Zohocorp ManageEngine Analytics Plus
Critical severity, CVSS 9.8. EPSS: 7.1% chance of exploitation in the next 30 days.
Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attackers to run arbitrary code.
Affected products
- Zohocorp ManageEngine Analytics Plus: version 2.9 only; version 3.0 only; version 3.1 only; version 3.2 only; version 3.3 only; version 3.4 only; …
Published 2022-08-15. Last modified 2026-06-17.