NA

CVE-2023-26600

Published: 06/03/2023 Updated: 13/03/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

This vulnerability allows remote malicious users to escalate privileges on affected installations of ManageEngine ServiceDesk Plus MSP. Authentication is required to exploit this vulnerability. The specific flaw exists within the generateSQLReport function. The issue results from the lack of proper validation of user-supplied data. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zohocorp manageengine supportcenter plus 11.0

zohocorp manageengine supportcenter plus

zohocorp manageengine assetexplorer 6.9

zohocorp manageengine assetexplorer

zohocorp manageengine servicedesk plus msp

zohocorp manageengine servicedesk plus msp 13.0

zohocorp manageengine servicedesk plus 14.1

zohocorp manageengine servicedesk plus