CVE-2023-23073: XSS
Published Feb 1, 2023
·Updated
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via PO in the purchase component.
Affected Software
8 affected components
ZohoCorp ManageEngine ServiceDesk Plus=14.0
ZohoCorp ManageEngine ServiceDesk Plus=14.0-14000
ZohoCorp ManageEngine ServiceDesk Plus=14.0-14001
ZohoCorp ManageEngine ServiceDesk Plus=14.0-14002
ZohoCorp ManageEngine ServiceDesk Plus=14.0-14003
ZohoCorp ManageEngine ServiceDesk Plus=14.0-14004
ZohoCorp ManageEngine ServiceDesk Plus=14.0-14005
ZohoCorp ManageEngine ServiceDesk Plus=14.0-14006
Event History
Feb 1, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-23073?
CVE-2023-23073 is a Cross-Site Scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14.
2
How does CVE-2023-23073 impact Zoho ManageEngine ServiceDesk Plus 14?
CVE-2023-23073 can be exploited through a PO in the purchase component of Zoho ManageEngine ServiceDesk Plus 14, leading to potential Cross-Site Scripting (XSS) attacks.
3
What is the severity of CVE-2023-23073?
CVE-2023-23073 has a severity value of 6.1, which is considered medium.
4
How can I fix CVE-2023-23073?
To fix CVE-2023-23073, it is recommended to update Zoho ManageEngine ServiceDesk Plus 14 to the latest version, as specified in the vendor's advisory.
5
Where can I find more information about CVE-2023-23073?
You can find more information about CVE-2023-23073 on the Zoho ManageEngine ServiceDesk Plus website and the bug bounty page.