CVE-2023-29443
26.04.2023, 21:15
Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint.Enginsight
Vendor | Product | Version |
---|---|---|
zohocorp | manageengine_assetexplorer | 6.9:6980 |
zohocorp | manageengine_assetexplorer | 6.9:6981 |
zohocorp | manageengine_assetexplorer | 6.9:6982 |
zohocorp | manageengine_assetexplorer | 6.9:6983 |
zohocorp | manageengine_assetexplorer | 6.9:6984 |
zohocorp | manageengine_assetexplorer | 6.9:6985 |
zohocorp | manageengine_assetexplorer | 6.9:6986 |
zohocorp | manageengine_assetexplorer | 6.9:6987 |
zohocorp | manageengine_assetexplorer | 6.9:6988 |
zohocorp | manageengine_servicedesk_plus | 𝑥 < 14.1 |
zohocorp | manageengine_servicedesk_plus | 14.1 |
zohocorp | manageengine_servicedesk_plus | 14.1:14100 |
zohocorp | manageengine_servicedesk_plus | 14.1:14101 |
zohocorp | manageengine_servicedesk_plus | 14.1:14102 |
zohocorp | manageengine_servicedesk_plus | 14.1:14103 |
zohocorp | manageengine_servicedesk_plus | 14.1:14104 |
zohocorp | manageengine_servicedesk_plus_msp | 𝑥 < 14.0 |
zohocorp | manageengine_servicedesk_plus_msp | 14.0:14000 |
zohocorp | manageengine_servicedesk_plus_msp | 14.0:14001 |
zohocorp | manageengine_supportcenter_plus | 𝑥 < 14.0 |
zohocorp | manageengine_supportcenter_plus | 14.0:14000 |
zohocorp | manageengine_supportcenter_plus | 14.0:14001 |
𝑥
= Vulnerable software versions