ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.
References
Link | Resource |
---|---|
https://labs.integrity.pt/advisories/cve-2017-9362 | Exploit Vendor Advisory |
Configurations
Information
Published : 2019-03-25 09:29
Updated : 2019-04-02 05:53
NVD link : CVE-2017-9362
Mitre link : CVE-2017-9362
JSON object : View
CWE
CWE-611
Improper Restriction of XML External Entity Reference
Products Affected
zohocorp
- manageengine_servicedesk_plus