Description
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.pdf.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
The vulnerability has been fixed in the latest version of Desktop Central.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54615 | A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.pdf. |
References
History
No history.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-09-05T13:59:05.415Z
Reserved: 2023-09-05T11:46:02.198Z
Link: CVE-2023-4768
Updated: 2024-08-02T07:37:59.679Z
Status : Modified
Published: 2023-11-03T11:15:08.440
Modified: 2024-11-21T08:35:56.537
Link: CVE-2023-4768
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD