First published: Fri Nov 03 2023(Updated: )
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.csv.
Credit: cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
=9.1.0 |
The vulnerability has been fixed in the latest version of Desktop Central.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-4767.
The severity level of the CVE-2023-4767 vulnerability is medium.
The affected software for the CVE-2023-4767 vulnerability is Zohocorp Manageengine Desktop Central version 9.1.0.
A remote attacker can exploit the CVE-2023-4767 vulnerability by injecting arbitrary HTTP headers and performing HTTP response splitting attacks via the fileName parameter.
Yes, it is recommended to update Manageengine Desktop Central to a version that is not affected by the CVE-2023-4767 vulnerability.