5
CVSSv2

CVE-2022-23779

Published: 02/03/2022 Updated: 09/03/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Zoho ManageEngine Desktop Central prior to 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zohocorp manageengine desktop central

Github Repositories

Internal Hostname Disclosure Vulnerability

Zoho_CVE-2022-23779 Internal Hostname Disclosure Vulnerability Proof-of-Concept Exploit Step 1: curl -ILk IP:port/themes Step 2: Read the HTTP redirect response and anaylze the Location HTTP response header [PoC] Follow us Vulnmachines Platform YouTube Twitter Facebook LinkedIn

CVE-2022-23779: Internal Hostname Disclosure Vulnerability

CVE-2022-23779: Internal Hostname Disclosure Vulnerability Information Description: Zoho ManageEngine Desktop Central before 10121378 exposes the installed server name to anyone The internal hostname can be discovered by reading HTTP redirect responses Versions Affected: <10121377 Researcher: Matthew Zellner (@fbusr) Disclosure Link: wwwmanageenginecom