QID 378382
Date Published: 2023-05-08
QID 378382: Zoho ManageEngine ServiceDesk Plus MSP Unauthenticated Arbitrary web-root File Disclosure Vulnerability
Zoho ManageEngine ServiceDesk Plus MSP is vulnerable to unauthenticated arbitrary web-root file disclosure vulnerability.
This vulnerability allows arbitrary web-root file access to unauthenticated users due to a flaw in handling request paths. Browsing to /sample/WEB-INF/web.xml allows for pre-authenticated arbitrary web-root file access to the contents of /WEBINF/web.xml.
Affected Versions:
ManageEngine ServiceDesk Plus MSP versions 10603 and below
QID Detection Logic (Authenticated):
Windows: Checks for vulnerable version of ManageEngine ServiceDesk Plus MSP by reading the version from buildinfo.xml file.
Successful exploitation of this vulnerability may allow an unauthenticated web-root file access to the attacker.
Solution
Vendor has released patches addressing the vulnerability. For more information please refer to Zoho ManageEngine Security Advisory
Vendor References
- Zoho ManageEngine Security Advisory -
www.manageengine.com/products/service-desk-msp/CVE-2022-32551.html
CVEs related to QID 378382
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Zoho ManageEngine Security Advisory |
|