OS Command Injection Vulnerability in Support Center Plus by Zoho Corporation
CVE-2023-23076
9.8CRITICAL
Key Information:
- Vendor
Zohocorp
- Vendor
- CVE Published:
- 1 February 2023
What is CVE-2023-23076?
An OS command injection vulnerability exists in Support Center Plus 11, which is triggered through the Executor in Action feature when users create new schedules. This flaw can allow attackers to execute arbitrary commands on the host operating system, potentially compromising the system's integrity and confidentiality. Users of Support Center Plus are advised to apply the necessary updates to mitigate any associated risks.
References
EPSS Score
66% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved