PT-2023-30555 · Zoho · Manageengine Desktop Central
Rafael Pedrero
·
Published
2023-11-03
·
Updated
2023-11-13
·
CVE-2023-4767
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ManageEngine Desktop Central version 9.1.0
Description
A CRLF injection vulnerability has been found in ManageEngine Desktop Central. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the
fileName parameter in "/STATE ID/1613157927228/InvSWMetering.csv".Recommendations
For version 9.1.0, consider disabling access to the "/STATE ID/1613157927228/InvSWMetering.csv" endpoint until a patch is available. Restrict the use of the
fileName parameter to minimize the risk of exploitation.Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Manageengine Desktop Central