PT-2023-7559 · Zoho · Zoho Manageengine Recovery Manager Plus

Hir0Ot

·

Published

2023-11-22

·

Updated

2023-12-01

·

CVE-2023-48646

CVSS v2.0

8.3

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine RecoveryManager Plus versions prior to 6070
Description The issue allows admin users to execute arbitrary commands via proxy settings. This is due to a failure to neutralize special elements, which can be exploited by a remote attacker to execute arbitrary commands.
Recommendations For versions prior to 6070, update to version 6070 or later to resolve the issue. As a temporary workaround, consider restricting access to the proxy settings to minimize the risk of exploitation.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2023-08614
CVE-2023-48646
ZDI-23-1719

Affected Products

Zoho Manageengine Recovery Manager Plus