CVE-2020-21642: Zohocorp ManageEngine Analytics Plus

Critical severity, CVSS 9.8. EPSS: 7.1% chance of exploitation in the next 30 days.

Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attackers to run arbitrary code.

Affected products

  • Zohocorp ManageEngine Analytics Plus: version 2.9 only; version 3.0 only; version 3.1 only; version 3.2 only; version 3.3 only; version 3.4 only; …

Published 2022-08-15. Last modified 2026-06-17.