Description
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.csv.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
The vulnerability has been fixed in the latest version of Desktop Central.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54614 | A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.csv. |
References
History
No history.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-09-05T13:59:18.678Z
Reserved: 2023-09-05T11:46:01.204Z
Link: CVE-2023-4767
Updated: 2024-08-02T07:37:59.867Z
Status : Modified
Published: 2023-11-03T11:15:08.333
Modified: 2024-11-21T08:35:56.397
Link: CVE-2023-4767
No data.
OpenCVE Enrichment
No data.
EUVD