CVE-2023-22624: XEE
Published Jan 17, 2023
·Updated
Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks.
Affected Software
9 affected components
ZohoCorp ManageEngine Exchange Reporter Plus<5.7
ZohoCorp ManageEngine Exchange Reporter Plus=5.7-5700
ZohoCorp ManageEngine Exchange Reporter Plus=5.7-5701
ZohoCorp ManageEngine Exchange Reporter Plus=5.7-5702
ZohoCorp ManageEngine Exchange Reporter Plus=5.7-5703
ZohoCorp ManageEngine Exchange Reporter Plus=5.7-5704
ZohoCorp ManageEngine Exchange Reporter Plus=5.7-5705
ZohoCorp ManageEngine Exchange Reporter Plus=5.7-5706
ZohoCorp ManageEngine Exchange Reporter Plus=5.7-5707
Event History
Jan 17, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-22624?
CVE-2023-22624 is a vulnerability in Zoho ManageEngine Exchange Reporter Plus before version 5708 that allows attackers to conduct XXE attacks.
2
What is the severity of CVE-2023-22624?
CVE-2023-22624 has a severity rating of 7.5 (high).
3
Which software versions are affected by CVE-2023-22624?
CVE-2023-22624 affects Zoho ManageEngine Exchange Reporter Plus versions up to and including 5.7-5707.
4
How can attackers exploit CVE-2023-22624?
Attackers can exploit CVE-2023-22624 by conducting XXE (XML External Entity) attacks.
5
Is there a fix available for CVE-2023-22624?
Yes, a fix is available for CVE-2023-22624 by upgrading to version 5708 of Zoho ManageEngine Exchange Reporter Plus.