This document addresses a medium-severity vulnerability identified in specific configuration scenarios, which could potentially allow remote code execution in specific cases.
Severity: Medium
Fixed Builds:
Release Date: November 2024
Reported by: Zewei Zhang from NSFOCUS TIANJI Lab via ZohoCorp Bug Bounty Program
During specific configuration scenarios, an authenticated admin user could exploit a configuration flaw to perform remote code execution. This issue originated from third-party libraries and has been resolved by upgrading these components.
Note: This issue is not applicable to cloud versions of the product.
Upgrading to the latest version is strongly advised due to the critical nature of this vulnerability. To upgrade, follow the steps below:
If you have any questions or require additional information regarding this update, please don't hesitate to contact our support.