VYPR
Unrated severityNVD Advisory· Published Oct 7, 2021· Updated Aug 4, 2024

CVE-2021-37923

CVE-2021-37923

Description

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload leading to remote code execution.

Vulnerability

A critical vulnerability in Zoho ManageEngine ADManager Plus versions 7110 and prior allows unrestricted file upload. The product fails to properly validate or restrict the types of files that can be uploaded, enabling an attacker to upload arbitrary files including executable code. The vulnerability is rooted in the file upload functionality, which is reachable without specific authentication requirements in the default configuration, as described in the CVE description [1].

Exploitation

An attacker can exploit this vulnerability by sending a crafted HTTP request to the affected server, uploading a file containing malicious code. No authentication is required, and the attacker does not need prior access to the system. The attack can be executed remotely over the network, and no user interaction is needed. The attacker simply submits a file upload request with a payload that will be stored on the server [1].

Impact

Successful exploitation allows the attacker to achieve remote code execution on the vulnerable server. This means the attacker can run arbitrary commands with the privileges of the application, potentially leading to full compromise of the server, including data exfiltration, installation of malware, or further lateral movement within the network. The impact is critical due to the potential for complete system compromise, as evidenced by the CVSS score associated with this CVE [1].

Mitigation

The vulnerability is fixed in ManageEngine ADManager Plus build 7111 and later. Users are strongly advised to upgrade to the latest version. The release notes for version 7111 confirm the fix for this issue [1]. No workarounds are documented. If upgrading is not immediately possible, consider restricting network access to the ADManager Plus interface and implementing web application firewall rules to block suspicious file uploads, but these are not confirmed mitigations [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.