// For flags

CVE-2023-22624

 

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks.

Zoho ManageEngine Exchange Reporter Plus anterior a 5708 permite a los atacantes realizar ataques XXE.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2023-01-05 CVE Reserved
  • 2023-01-17 CVE Published
  • 2024-08-02 CVE Updated
  • 2024-08-09 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-611: Improper Restriction of XML External Entity Reference
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Zohocorp
Search vendor "Zohocorp"
Manageengine Exchange Reporter Plus
Search vendor "Zohocorp" for product "Manageengine Exchange Reporter Plus"
< 5.7
Search vendor "Zohocorp" for product "Manageengine Exchange Reporter Plus" and version " < 5.7"
-
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Exchange Reporter Plus
Search vendor "Zohocorp" for product "Manageengine Exchange Reporter Plus"
5.7
Search vendor "Zohocorp" for product "Manageengine Exchange Reporter Plus" and version "5.7"
5700
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Exchange Reporter Plus
Search vendor "Zohocorp" for product "Manageengine Exchange Reporter Plus"
5.7
Search vendor "Zohocorp" for product "Manageengine Exchange Reporter Plus" and version "5.7"
5701
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Exchange Reporter Plus
Search vendor "Zohocorp" for product "Manageengine Exchange Reporter Plus"
5.7
Search vendor "Zohocorp" for product "Manageengine Exchange Reporter Plus" and version "5.7"
5702
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Exchange Reporter Plus
Search vendor "Zohocorp" for product "Manageengine Exchange Reporter Plus"
5.7
Search vendor "Zohocorp" for product "Manageengine Exchange Reporter Plus" and version "5.7"
5703
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Exchange Reporter Plus
Search vendor "Zohocorp" for product "Manageengine Exchange Reporter Plus"
5.7
Search vendor "Zohocorp" for product "Manageengine Exchange Reporter Plus" and version "5.7"
5704
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Exchange Reporter Plus
Search vendor "Zohocorp" for product "Manageengine Exchange Reporter Plus"
5.7
Search vendor "Zohocorp" for product "Manageengine Exchange Reporter Plus" and version "5.7"
5705
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Exchange Reporter Plus
Search vendor "Zohocorp" for product "Manageengine Exchange Reporter Plus"
5.7
Search vendor "Zohocorp" for product "Manageengine Exchange Reporter Plus" and version "5.7"
5706
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Exchange Reporter Plus
Search vendor "Zohocorp" for product "Manageengine Exchange Reporter Plus"
5.7
Search vendor "Zohocorp" for product "Manageengine Exchange Reporter Plus" and version "5.7"
5707
Affected