Properties.do in ZOHO ManageEngine OpStor before build 8500 does not properly check privilege levels, which allows remote authenticated users to obtain Admin access by using the name parameter in conjunction with a true value of the edit parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Manageengine_opstor | Zohocorp | * | 8.3 (including) |