CVE-2023-48646: Zohocorp ManageEngine Recoverymanager Plus

High severity, CVSS 7.2. EPSS: 82.2% chance of exploitation in the next 30 days.

Zoho ManageEngine RecoveryManager Plus before 6070 allows admin users to execute arbitrary commands via proxy settings.

Affected products

  • Zohocorp ManageEngine Recoverymanager Plus: before 6.0 (fixed in 6.0); version 6.0 only

Published 2023-11-22. Last modified 2026-06-17.