Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-666p-v2mj-cxrf

Опубликовано: 16 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote attackers to read arbitrary files, enumerate folders and scan internal ports via crafted XML license file.

Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote attackers to read arbitrary files, enumerate folders and scan internal ports via crafted XML license file.

EPSS

Процентиль: 89%
0.04582
Низкий

7.5 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 7.5
nvd
больше 3 лет назад

Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote attackers to read arbitrary files, enumerate folders and scan internal ports via crafted XML license file.

EPSS

Процентиль: 89%
0.04582
Низкий

7.5 High

CVSS3

Дефекты

CWE-611