CVE-2018-18980
An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the RequestXML parameter in a /devices/ProcessRequest.do GET request.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 25.0%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the RequestXML parameter in a /devices/ProcessRequest.do GET request. For example, the attacker can trigger the transmission of local files to an arbitrary remote FTP server.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 25.00% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- zohocorp/manageengine network configuration manager · zohocorp/manageengine opmanager
- Source
- cve@mitre.org
References
- https://github.com/x-f1v3/ForCve/issues/5Exploit, Third Party Advisory
- https://www.manageengine.com/network-monitoring/help/read-me.htmlVendor Advisory
- https://github.com/x-f1v3/ForCve/issues/5Exploit, Third Party Advisory
- https://www.manageengine.com/network-monitoring/help/read-me.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.