Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint.
References
Link | Resource |
---|---|
https://www.manageengine.com/products/service-desk/CVE-2023-29443.html | Vendor Advisory |
https://www.manageengine.com/products/service-desk/CVE-2023-29443.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 07:57
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.manageengine.com/products/service-desk/CVE-2023-29443.html - Vendor Advisory |
26 Jun 2023, 17:15
Type | Values Removed | Values Added |
---|---|---|
Summary | Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint. |
Information
Published : 2023-04-26 21:15
Updated : 2024-11-21 07:57
NVD link : CVE-2023-29443
Mitre link : CVE-2023-29443
CVE.ORG link : CVE-2023-29443
JSON object : View
Products Affected
zohocorp
- manageengine_assetexplorer
- manageengine_servicedesk_plus_msp
- manageengine_supportcenter_plus
- manageengine_servicedesk_plus
CWE
CWE-611
Improper Restriction of XML External Entity Reference