PT-2020-20194 · Zoho · Zoho Manageengine Desktop Central
Kalimer0X00
·
Published
2020-03-11
·
Updated
2021-07-21
·
CVE-2020-8540
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zoho ManageEngine Desktop Central versions prior to 07-Mar-2020 update
Description
A vulnerability allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. This issue can be exploited to access sensitive information or forge requests to internal servers.
Recommendations
For versions prior to the 07-Mar-2020 update, update to a version released after 07-Mar-2020 to resolve the issue. As a temporary workaround, consider restricting access to XML requests or disabling the XML parsing functionality until a patch is available.
Fix
SSRF
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zoho Manageengine Desktop Central