ZDI-CAN-21173: ZDI-23-1719: ManageEngine Recovery Manager Plus getEscapedValue Command Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of ManageEngine Recovery Manager Plus. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2023-48646.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-21173?
ZDI-CAN-21173 has a CVSS rating of 7.2, indicating a high severity vulnerability.
How do I fix ZDI-CAN-21173?
To fix ZDI-CAN-21173, ensure that you apply the latest security patches provided by ManageEngine for Recovery Manager Plus.
What systems are affected by ZDI-CAN-21173?
ZDI-CAN-21173 affects installations of ManageEngine Recovery Manager Plus.
Does ZDI-CAN-21173 require authentication to exploit?
Yes, ZDI-CAN-21173 requires authentication to exploit the vulnerability.
What can attackers do with ZDI-CAN-21173?
Attackers can execute arbitrary code on affected installations of ManageEngine Recovery Manager Plus due to ZDI-CAN-21173.