CVE-2023-29443

MEDIUM

ManageEngine AssetExplorer < 6989 - XML External Entity Injection via Reports Integration API

Title source: llm
STIX 2.1

Description

Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint.

References (1)

Core 1

Scores

CVSS v3 4.9
EPSS 0.0583
EPSS Percentile 90.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-611
Status published
Products (7)
zohocorp/manageengine_assetexplorer 6.9 6980 (9 CPE variants)
zohocorp/manageengine_servicedesk_plus 14.1 (6 CPE variants)
zohocorp/manageengine_servicedesk_plus < 14.1
zohocorp/manageengine_servicedesk_plus_msp 14.0 14000 (2 CPE variants)
zohocorp/manageengine_servicedesk_plus_msp < 14.0
zohocorp/manageengine_supportcenter_plus 14.0 14000 (2 CPE variants)
zohocorp/manageengine_supportcenter_plus < 14.0
Published Apr 26, 2023
Tracked Since Feb 18, 2026