QID 378355
Date Published: 2023-04-17
QID 378355: Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, SupportCenter Plus and AssetExplorer Extensible Markup Language (XML) External Entity (XXE) Vulnerability
Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, SupportCenter Plus and AssetExplorer are vulnerable to XXE vulnerability when integrating with Analytics Plus.
Threat actors with admin role access can retrieve local files from the server running the affected products.
Affected Versions:
ServiceDesk Plus versions 14000 and below
ServiceDesk Plus MSP versions 13000 and below
SupportCenter Plus versions 11025 and below
AssetExplorer version 6980
QID Detection Logic (Authenticated):
Windows: Checks for vulnerable version of ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, SupportCenter Plus and AssetExplorer by reading the version from buildinfo.xml file.
Successful exploitation of this vulnerability may allow threat actors with admin role access can retrieve local files from the server running the affected products.
- Zoho ManageEngine Security Advisory -
www.manageengine.com/products/service-desk/CVE-2022-40771.html
CVEs related to QID 378355
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Zoho ManageEngine Security Advisory |
|