First published: Wed Feb 01 2023(Updated: )
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via embedding videos in the language component.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Servicedesk Plus | =14.0 | |
Zohocorp Manageengine Servicedesk Plus | =14.0-14000 | |
Zohocorp Manageengine Servicedesk Plus | =14.0-14001 | |
Zohocorp Manageengine Servicedesk Plus | =14.0-14002 | |
Zohocorp Manageengine Servicedesk Plus | =14.0-14003 | |
Zohocorp Manageengine Servicedesk Plus | =14.0-14004 | |
Zohocorp Manageengine Servicedesk Plus | =14.0-14005 | |
Zohocorp Manageengine Servicedesk Plus | =14.0-14006 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23074 is a cross-site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 that can be exploited by embedding videos in the language component.
CVE-2023-23074 affects Zoho ManageEngine ServiceDesk Plus version 14.0 and can be exploited through embedding videos in the language component.
CVE-2023-23074 has a severity rating of 6.1 (medium).
We do not provide guidance on how to exploit vulnerabilities. It is important to follow responsible disclosure practices and report vulnerabilities to the software vendor.
To fix CVE-2023-23074, it is recommended to update Zoho ManageEngine ServiceDesk Plus to the latest version available, as it may contain a patch for the vulnerability. Additionally, users should be cautious when embedding videos in the language component.