QID 378341

Date Published: 2023-04-10

QID 378341: Zoho ManageEngine SupportCenter Plus OS Command Injection Vulnerability

Zoho ManageEngine SupportCenter Plus is vulnerable to OS command injection vulnerability.

An OS command injection vulnerability allows a user with the admin role to inject and run OS commands in the target server.

Affected Versions:
SupportCenter Plus 11027 and older

QID Detection Logic (Authenticated):
Windows: Checks for vulnerable version of ManageEngine SupportCenter Plus by reading the version from buildinfo.xml file.

Successful exploitation of this vulnerability may allow an attacker with the admin role to inject and run OS commands in the target server.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Vendor has released patches addressing the vulnerability. For more information please refer to Zoho ManageEngine Security Advisory

    Vendor References

    CVEs related to QID 378341

    Software Advisories
    Advisory ID Software Component Link
    Zoho ManageEngine Security Advisory URL Logo www.manageengine.com/products/support-center/CVE-2023-23076.html