PT-2023-18836 · Zoho · Zoho Manageengine Servicedesk Plus
Hms
·
Publicado
2023-02-01
·
Atualizado
2023-02-22
·
CVE-2023-23078
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Zoho ManageEngine ServiceDesk Plus version 14
Description
The issue is related to a cross site scripting (XSS) vulnerability. It occurs via the comment field when changing the credentials in the Assets.
Recommendations
For Zoho ManageEngine ServiceDesk Plus version 14, consider disabling the comment field when changing credentials in the Assets as a temporary workaround until a patch is available. Restrict access to the Assets module to minimize the risk of exploitation. Avoid using the comment field in the affected area until the issue is resolved.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Zoho Manageengine Servicedesk Plus