CVE-2020-24743: Zohocorp ManageEngine Applications Manager

Critical severity, CVSS 9.8. EPSS: 2.8% chance of exploitation in the next 30 days.

An issue was found in /showReports.do Zoho ManageEngine Applications Manager up to 14550, allows attackers to gain escalated privileges via the resourceid parameter.

Affected products

  • Zohocorp ManageEngine Applications Manager: before 14.5 (fixed in 14.5); version 14.5 only

Published 2021-11-03. Last modified 2026-06-17.