PT-2023-7559 · Zoho · Zoho Manageengine Recovery Manager Plus

·

CVE-2023-48646

·

Published

2023-11-22

·

Updated

2023-12-01

CVSS v2.0

8.3

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine RecoveryManager Plus versions prior to 6070
Description The issue allows admin users to execute arbitrary commands via proxy settings. This is due to a failure to neutralize special elements, which can be exploited by a remote attacker to execute arbitrary commands.
Recommendations For versions prior to 6070, update to version 6070 or later to resolve the issue. As a temporary workaround, consider restricting access to the proxy settings to minimize the risk of exploitation.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-08614
CVE-2023-48646
ZDI-23-1719

Affected Products

Zoho Manageengine Recovery Manager Plus