XML External Entity Injection Vulnerability in Zoho ManageEngine AssetExplorer
CVE-2019-14693

8.5HIGH

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
8 August 2019

What is CVE-2019-14693?

Zoho ManageEngine AssetExplorer 6.2.0 is susceptible to an XML External Entity Injection vulnerability when handling license XML data. This flaw allows remote attackers to exploit the application, potentially exposing sensitive information or consuming system memory resources, which can lead to various security risks. Proper validation of XML input is necessary to mitigate this type of vulnerability.

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.