4.9

CVE-2023-35786

Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZohocorpManageengine Admanager Plus Version7.1 Update-
ZohocorpManageengine Admanager Plus Version7.1 Update7100
ZohocorpManageengine Admanager Plus Version7.1 Update7101
ZohocorpManageengine Admanager Plus Version7.1 Update7102
ZohocorpManageengine Admanager Plus Version7.1 Update7110
ZohocorpManageengine Admanager Plus Version7.1 Update7111
ZohocorpManageengine Admanager Plus Version7.1 Update7112
ZohocorpManageengine Admanager Plus Version7.1 Update7113
ZohocorpManageengine Admanager Plus Version7.1 Update7114
ZohocorpManageengine Admanager Plus Version7.1 Update7115
ZohocorpManageengine Admanager Plus Version7.1 Update7116
ZohocorpManageengine Admanager Plus Version7.1 Update7117
ZohocorpManageengine Admanager Plus Version7.1 Update7118
ZohocorpManageengine Admanager Plus Version7.1 Update7120
ZohocorpManageengine Admanager Plus Version7.1 Update7121
ZohocorpManageengine Admanager Plus Version7.1 Update7122
ZohocorpManageengine Admanager Plus Version7.1 Update7123
ZohocorpManageengine Admanager Plus Version7.1 Update7124
ZohocorpManageengine Admanager Plus Version7.1 Update7125
ZohocorpManageengine Admanager Plus Version7.1 Update7126
ZohocorpManageengine Admanager Plus Version7.1 Update7130
ZohocorpManageengine Admanager Plus Version7.1 Update7131
ZohocorpManageengine Admanager Plus Version7.1 Update7140
ZohocorpManageengine Admanager Plus Version7.1 Update7141
ZohocorpManageengine Admanager Plus Version7.1 Update7150
ZohocorpManageengine Admanager Plus Version7.1 Update7151
ZohocorpManageengine Admanager Plus Version7.1 Update7160
ZohocorpManageengine Admanager Plus Version7.1 Update7161
ZohocorpManageengine Admanager Plus Version7.1 Update7162
ZohocorpManageengine Admanager Plus Version7.1 Update7163
ZohocorpManageengine Admanager Plus Version7.1 Update7170
ZohocorpManageengine Admanager Plus Version7.1 Update7171
ZohocorpManageengine Admanager Plus Version7.1 Update7180
ZohocorpManageengine Admanager Plus Version7.1 Update7181
ZohocorpManageengine Admanager Plus Version7.1 Update7182
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.43% 0.614
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.