CVE-2023-29443

Severity
4.9MEDIUM
EPSS
0.6%
top 30.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 26

Description

Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 1.2 | Impact: 3.6

🔴Vulnerability Details

2
CVEList
CVE-2023-29443: Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 all2023-04-26
GHSA
GHSA-h7wh-8cwv-qqm6: Zoho ManageEngine ServiceDesk Plus through 14104 allows admin users to conduct an XXE attack2023-04-26
CVE-2023-29443 (MEDIUM CVSS 4.9) | Zoho ManageEngine ServiceDesk Plus | cvebase.io