A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.pdf.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54615 | A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.pdf. |
Fixes
Solution
The vulnerability has been fixed in the latest version of Desktop Central.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-09-05T13:59:05.415Z
Reserved: 2023-09-05T11:46:02.198Z
Link: CVE-2023-4768
Updated: 2024-08-02T07:37:59.679Z
Status : Modified
Published: 2023-11-03T11:15:08.440
Modified: 2024-11-21T08:35:56.537
Link: CVE-2023-4768
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD