← back
CVE-2023-29443

CVE-2023-29443

CVSS 4.9 MEDIUMEPSS 3.0%CWE-611
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.9EPSS 3.0%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
26 Apr 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Affected products
n/a · n/a

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →