Description
An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the RequestXML parameter in a /devices/ProcessRequest.do GET request. For example, the attacker can trigger the transmission of local files to an arbitrary remote FTP server.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T17:54:36.803Z
Reserved: 2018-11-05T00:00:00.000Z
Link: CVE-2018-18980
No data.
Status : Modified
Published: 2018-11-06T04:29:00.347
Modified: 2024-11-21T03:56:58.647
Link: CVE-2018-18980
No data.
OpenCVE Enrichment
No data.
Weaknesses