4.9
CVE-2023-35786
- EPSS 0.43%
- Published 05.07.2023 06:15:21
- Last modified 21.11.2024 08:08:42
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files.
Data is provided by the National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Admanager Plus Version < 7.1
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update-
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7100
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7101
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7102
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7110
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7111
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7112
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7113
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7114
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7115
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7116
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7117
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7118
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7120
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7121
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7122
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7123
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7124
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7125
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7126
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7130
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7131
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7140
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7141
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7150
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7151
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7160
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7161
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7162
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7163
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7170
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7171
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7180
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7181
Zohocorp ≫ Manageengine Admanager Plus Version7.1 Update7182
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.43% | 0.614 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
CWE-611 Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.