An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the RequestXML parameter in a /devices/ProcessRequest.do GET request. For example, the attacker can trigger the transmission of local files to an arbitrary remote FTP server.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T17:54:36.803Z
Reserved: 2018-11-05T00:00:00Z
Link: CVE-2018-18980
No data.
Status : Modified
Published: 2018-11-06T04:29:00.347
Modified: 2024-11-21T03:56:58.647
Link: CVE-2018-18980
No data.
OpenCVE Enrichment
No data.
Weaknesses