CVE-2023-4767: Improper Neutralization of CRLF Sequences in ManageEngine Desktop Central
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATEID/1613157927228/InvSWMetering.csv.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-4767.
What is the severity level of the CVE-2023-4767 vulnerability?
The severity level of the CVE-2023-4767 vulnerability is medium.
What is the affected software for the CVE-2023-4767 vulnerability?
The affected software for the CVE-2023-4767 vulnerability is Zohocorp Manageengine Desktop Central version 9.1.0.
How can a remote attacker exploit the CVE-2023-4767 vulnerability?
A remote attacker can exploit the CVE-2023-4767 vulnerability by injecting arbitrary HTTP headers and performing HTTP response splitting attacks via the fileName parameter.
Is there a fix available for the CVE-2023-4767 vulnerability?
Yes, it is recommended to update Manageengine Desktop Central to a version that is not affected by the CVE-2023-4767 vulnerability.