Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint.
References
Link | Resource |
---|---|
https://www.manageengine.com/products/service-desk/CVE-2023-29443.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2023-04-26 21:15
Updated : 2023-06-26 17:15
NVD link : CVE-2023-29443
Mitre link : CVE-2023-29443
CVE.ORG link : CVE-2023-29443
JSON object : View
Products Affected
zohocorp
- manageengine_assetexplorer
- manageengine_servicedesk_plus_msp
- manageengine_supportcenter_plus
- manageengine_servicedesk_plus
CWE
CWE-611
Improper Restriction of XML External Entity Reference