PT-2023-18594 · Zoho · Zoho Manageengine Exchange Reporter Plus

Kyodream

·

Publicado

2023-01-17

·

Atualizado

2023-01-23

·

CVE-2023-22624

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine Exchange Reporter Plus versions prior to 5708
Description The issue allows attackers to conduct XXE (XML External Entity) attacks. This type of attack occurs when an application parses XML input that contains malicious external entity references, which can lead to unauthorized access to sensitive data or other malicious activities.
Recommendations For versions prior to 5708, update to version 5708 or later to resolve the issue. As a temporary workaround, consider restricting XML input parsing to minimize the risk of exploitation.

Correção

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-22624

Produtos afetados

Zoho Manageengine Exchange Reporter Plus