PT-2023-30569 · Zoho · Manageengine Desktop Central
Rafael Pedrero
·
Published
2023-11-03
·
Updated
2023-11-13
·
CVE-2023-4769
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ManageEngine Desktop Central version 9.1.0
Description
A Server-Side Request Forgery (SSRF) vulnerability has been found, specifically affecting the /smtpConfig.do component. This issue could allow an authenticated attacker to launch targeted attacks, such as cross-port attacks, service enumeration, and other attacks via HTTP requests.
Recommendations
For version 9.1.0, consider disabling access to the /smtpConfig.do component as a temporary workaround until a patch is available. Restricting the use of this component can help minimize the risk of exploitation.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Manageengine Desktop Central