XML External Entity Injection Vulnerability in Zoho ManageEngine AssetExplorer
CVE-2019-14693
8.5HIGH
What is CVE-2019-14693?
Zoho ManageEngine AssetExplorer 6.2.0 is susceptible to an XML External Entity Injection vulnerability when handling license XML data. This flaw allows remote attackers to exploit the application, potentially exposing sensitive information or consuming system memory resources, which can lead to various security risks. Proper validation of XML input is necessary to mitigate this type of vulnerability.