High severity8.8NVD Advisory· Published Sep 4, 2017· Updated May 13, 2026
CVE-2017-14123
CVE-2017-14123
Description
Zoho ManageEngine Firewall Analyzer 12200 has an unrestricted File Upload vulnerability in the "Group Chat" section. Any user can upload files with any extensions. By uploading a PHP file to the server, an attacker can cause it to execute in the server context, as demonstrated by /itplus/FileStorage/302/shell.jsp.
Affected products
1- cpe:2.3:a:zohocorp:manageengine_firewall_analyzer:12.2:12200:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- pitstop.manageengine.com/portal/kb/articles/latest-consolidated-patchnvdPatchVendor Advisory
- blogs.securiteam.com/index.php/archives/3228nvdExploitPatchThird Party Advisory
News mentions
0No linked articles in our index yet.