Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m2r7-w5rx-6vqg

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An XML external entity (XXE) vulnerability iin Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

An XML external entity (XXE) vulnerability iin Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

EPSS

Процентиль: 96%
0.24116
Средний

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 9.8
nvd
почти 6 лет назад

An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

EPSS

Процентиль: 96%
0.24116
Средний

Дефекты

CWE-611