PT-2023-30562 · Zoho · Manageengine Desktop Central

·

CVE-2023-4768

·

Published

2023-11-03

·

Updated

2023-11-13

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ManageEngine Desktop Central version 9.1.0
Description A CRLF injection vulnerability has been found in ManageEngine Desktop Central. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in "/STATE ID/1613157927228/InvSWMetering.pdf".
Recommendations For version 9.1.0, consider disabling access to the "/STATE ID/1613157927228/InvSWMetering.pdf" endpoint until a patch is available. Restrict the use of the fileName parameter in this endpoint to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-4768

Affected Products

Manageengine Desktop Central