Critical severity9.1NVD Advisory· Published Jun 6, 2018· Updated Jun 17, 2026
CVE-2018-11808
CVE-2018-11808
Description
Incorrect Access Control in CustomFieldsFeedServlet in Zoho ManageEngine Applications Manager Version 13 before build 13740 allows an attacker to delete any file and read certain files on the server in the context of the user (which by default is "NT AUTHORITY / SYSTEM") by sending a specially crafted request to the server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <13740
- Range: <13.13740
Patches
Vulnerability mechanics
References
3- www.securityfocus.com/bid/104467nvdThird Party AdvisoryVDB Entry
- www.manageengine.com/products/applications_manager/issues.htmlnvdRelease NotesVendor Advisory
- www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2018-11808.htmlnvd
News mentions
0No linked articles in our index yet.