First published: Fri Nov 03 2023(Updated: )
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.pdf.
Credit: cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
=9.1.0 |
The vulnerability has been fixed in the latest version of Desktop Central.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4768 is a CRLF injection vulnerability found in ManageEngine Desktop Central version 9.1.0.
The severity of CVE-2023-4768 is medium with a CVSS score of 6.1.
CVE-2023-4768 allows a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks using the fileName parameter.
ManageEngine Desktop Central version 9.1.0 is affected by CVE-2023-4768.
To fix CVE-2023-4768, update to a version of ManageEngine Desktop Central that is not affected by the vulnerability.