Impact
An authenticated path traversal flaw exists in the Exchange Online backup module of ManageEngine M365 Manager Plus and M365 Security Plus. The flaw allows a logged‑in user with sufficient privileges to craft requests that resolve to files outside the intended backup directory, enabling read access to arbitrary files on the server without any additional authentication or escalation. This could lead to disclosure of sensitive configuration files, credentials, or other confidential data. The weakness is classified as CWE‑23.
Affected Systems
The vulnerability affects Zohocorp’s ManageEngine M365 Manager Plus and M365 Security Plus products for all releases with a version number less than 4820. Users should verify their installed version against this threshold.
Risk and Exploitability
The CVSS base score of 8.5 indicates high severity, and the EPSS score is not available. The vulnerability is not yet listed in the CISA KEV catalog, but the lack of a low EPSS rating does not eliminate potential exploitation risk. Attackers would need valid credentials within the target system to exploit this flaw, suggesting an internal or compromised account could be used to read sensitive files. Once the path traversal is successful, the attacker could harvest sensitive data or further pivot within the environment.
OpenCVE Enrichment