Description
An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the RequestXML parameter in a /devices/ProcessRequest.do GET request. For example, the attacker can trigger the transmission of local files to an arbitrary remote FTP server.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T17:54:36.803Z
Reserved: 2018-11-05T00:00:00.000Z
Link: CVE-2018-18980
No data.
Status : Modified
Published: 2018-11-06T04:29:00.347
Modified: 2024-11-21T03:56:58.647
Link: CVE-2018-18980
No data.
OpenCVE Enrichment
No data.
Weaknesses