XML External Entity Injection in Zoho ManageEngine Firewall Analyzer
CVE-2019-11677
9.8CRITICAL
What is CVE-2019-11677?
The Custom Report import function in Zoho ManageEngine Firewall Analyzer prior to version 12.3 Build 123224 is susceptible to an XML External Entity (XXE) Injection vulnerability. This flaw could allow attackers to interfere with the processing of XML data, potentially leading to exposure of sensitive information or further exploitation within the network environment.