First published: Wed Nov 22 2023(Updated: )
Zoho ManageEngine RecoveryManager Plus before 6070 allows admin users to execute arbitrary commands via proxy settings.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Recoverymanager Plus | <6.0 | |
Zohocorp Manageengine Recoverymanager Plus | =6.0-build6001 | |
Zohocorp Manageengine Recoverymanager Plus | =6.0-build6003 | |
Zohocorp Manageengine Recoverymanager Plus | =6.0-build6005 | |
Zohocorp Manageengine Recoverymanager Plus | =6.0-build6011 | |
Zohocorp Manageengine Recoverymanager Plus | =6.0-build6016 | |
Zohocorp Manageengine Recoverymanager Plus | =6.0-build6017 | |
Zohocorp Manageengine Recoverymanager Plus | =6.0-build6020 | |
Zohocorp Manageengine Recoverymanager Plus | =6.0-build6025 | |
Zohocorp Manageengine Recoverymanager Plus | =6.0-build6026 | |
Zohocorp Manageengine Recoverymanager Plus | =6.0-build6030 | |
Zohocorp Manageengine Recoverymanager Plus | =6.0-build6031 | |
Zohocorp Manageengine Recoverymanager Plus | =6.0-build6032 | |
Zohocorp Manageengine Recoverymanager Plus | =6.0-build6041 | |
Zohocorp Manageengine Recoverymanager Plus | =6.0-build6042 | |
Zohocorp Manageengine Recoverymanager Plus | =6.0-build6043 | |
Zohocorp Manageengine Recoverymanager Plus | =6.0-build6044 | |
Zohocorp Manageengine Recoverymanager Plus | =6.0-build6047 | |
Zohocorp Manageengine Recoverymanager Plus | =6.0-build6049 | |
Zohocorp Manageengine Recoverymanager Plus | =6.0-build6050 | |
Zohocorp Manageengine Recoverymanager Plus | =6.0-build6051 | |
Zohocorp Manageengine Recoverymanager Plus | =6.0-build6053 | |
Zohocorp Manageengine Recoverymanager Plus | =6.0-build6054 | |
Zohocorp Manageengine Recoverymanager Plus | =6.0-build6056 | |
Zohocorp Manageengine Recoverymanager Plus | =6.0-build6057 | |
Zohocorp Manageengine Recoverymanager Plus | =6.0-build6058 | |
Zohocorp Manageengine Recoverymanager Plus | =6.0-build6060 | |
Zohocorp Manageengine Recoverymanager Plus | =6.0-build6061 | |
Zohocorp Manageengine Recoverymanager Plus | =6.0-build6062 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-48646 is a vulnerability in Zoho ManageEngine RecoveryManager Plus that allows admin users to execute arbitrary commands via proxy settings.
CVE-2023-48646 has a severity rating of 7.2, which is considered high.
Zoho ManageEngine RecoveryManager Plus versions 6.0 to 6.0-build6062 are affected by CVE-2023-48646.
Admin users can exploit CVE-2023-48646 by manipulating proxy settings to execute arbitrary commands.
Yes, Zoho patched the vulnerability. Users should update to version 6.0-build6070 or later to fix CVE-2023-48646.