First published: Tue Jan 17 2023(Updated: )
Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp ManageEngine Exchange Reporter Plus | <5.7 | |
Zohocorp ManageEngine Exchange Reporter Plus | =5.7-5700 | |
Zohocorp ManageEngine Exchange Reporter Plus | =5.7-5701 | |
Zohocorp ManageEngine Exchange Reporter Plus | =5.7-5702 | |
Zohocorp ManageEngine Exchange Reporter Plus | =5.7-5703 | |
Zohocorp ManageEngine Exchange Reporter Plus | =5.7-5704 | |
Zohocorp ManageEngine Exchange Reporter Plus | =5.7-5705 | |
Zohocorp ManageEngine Exchange Reporter Plus | =5.7-5706 | |
Zohocorp ManageEngine Exchange Reporter Plus | =5.7-5707 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-22624 is a vulnerability in Zoho ManageEngine Exchange Reporter Plus before version 5708 that allows attackers to conduct XXE attacks.
CVE-2023-22624 has a severity rating of 7.5 (high).
CVE-2023-22624 affects Zoho ManageEngine Exchange Reporter Plus versions up to and including 5.7-5707.
Attackers can exploit CVE-2023-22624 by conducting XXE (XML External Entity) attacks.
Yes, a fix is available for CVE-2023-22624 by upgrading to version 5708 of Zoho ManageEngine Exchange Reporter Plus.