XXE Vulnerability in Zoho ManageEngine ADManager Plus
CVE-2023-35786
4.9MEDIUM
What is CVE-2023-35786?
An XML External Entity (XXE) vulnerability allows attackers with administrative access to Zoho ManageEngine ADManager Plus (versions prior to 7183) to exploit the system and gain unauthorized access to sensitive files. This issue can lead to potential information disclosure, thereby compromising the integrity and confidentiality of the affected systems and data.
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved