Zoho ManageEngine Analytics Plus OOB XML External Entity Vulnerability v<4.3.5
CVE-2020-21641 Published on August 15, 2022

Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote attackers to read arbitrary files, enumerate folders and scan internal ports via crafted XML license file.

NVD


Products Associated with CVE-2020-21641

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2020-21641 are published in Zoho Corp Manageengine Analytics Plus:

 

Exploit Probability

EPSS
4.58%
Percentile
89.00%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.