CVE-2020-15594: SSRF
An SSRF issue was discovered in Zoho Application Control Plus before version 10.0.511. The mail gateway configuration feature allows an attacker to perform a scan in order to discover open ports on a machine as well as available machines on the network segment on which the instance of the product is deployed.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-15594?
CVE-2020-15594 is an SSRF (Server-Side Request Forgery) vulnerability discovered in Zoho Application Control Plus before version 10.0.511.
How does CVE-2020-15594 affect Zoho Application Control Plus?
CVE-2020-15594 allows an attacker to perform a port scan and discover available machines on the network segment where Zoho Application Control Plus is installed.
What is the severity of CVE-2020-15594?
The severity of CVE-2020-15594 is medium, with a CVSS score of 4.3.
How can I fix CVE-2020-15594?
To fix CVE-2020-15594, update Zoho Application Control Plus to version 10.0.511 or later.
Where can I find more information about CVE-2020-15594?
You can find more information about CVE-2020-15594 at https://excellium-services.com/cert-xlm-advisory/cve-2020-15594/.