First published: Tue Sep 29 2020(Updated: )
An SSRF issue was discovered in Zoho Application Control Plus before version 10.0.511. The mail gateway configuration feature allows an attacker to perform a scan in order to discover open ports on a machine as well as available machines on the network segment on which the instance of the product is deployed.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zoho ManageEngine | <10.0.511 | |
Zohocorp Manageengine Application Control Plus | <10.0.511 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15594 is an SSRF (Server-Side Request Forgery) vulnerability discovered in Zoho Application Control Plus before version 10.0.511.
CVE-2020-15594 allows an attacker to perform a port scan and discover available machines on the network segment where Zoho Application Control Plus is installed.
The severity of CVE-2020-15594 is medium, with a CVSS score of 4.3.
To fix CVE-2020-15594, update Zoho Application Control Plus to version 10.0.511 or later.
You can find more information about CVE-2020-15594 at https://excellium-services.com/cert-xlm-advisory/cve-2020-15594/.