OS Command Injection Vulnerability in Support Center Plus by Zoho Corporation
CVE-2023-23076

9.8CRITICAL

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
1 February 2023

What is CVE-2023-23076?

An OS command injection vulnerability exists in Support Center Plus 11, which is triggered through the Executor in Action feature when users create new schedules. This flaw can allow attackers to execute arbitrary commands on the host operating system, potentially compromising the system's integrity and confidentiality. Users of Support Center Plus are advised to apply the necessary updates to mitigate any associated risks.

References

EPSS Score

66% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.