A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.csv.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54614 | A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.csv. |
Fixes
Solution
The vulnerability has been fixed in the latest version of Desktop Central.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-09-05T13:59:18.678Z
Reserved: 2023-09-05T11:46:01.204Z
Link: CVE-2023-4767
Updated: 2024-08-02T07:37:59.867Z
Status : Modified
Published: 2023-11-03T11:15:08.333
Modified: 2024-11-21T08:35:56.397
Link: CVE-2023-4767
No data.
OpenCVE Enrichment
No data.
EUVD