CVE ID : CVE-2023-29443
Product Name | Severity | Affected Version(s) | Fixed Version | Fixed On |
---|---|---|---|---|
ServiceDesk Plus | Low | 14104 and below | 14105 | Feb. 20, 2023 |
ServiceDesk Plus MSP | Low | 14001 and below | 14200 | Apr. 10, 2023 |
SupportCenter Plus | Low | 14001 and below | 14200 | Apr. 24, 2023 |
AssetExplorer | Low | 6980 to 6988 | 6989 | Feb. 20, 2023 |
Details
A threat actor with the SDAdmin role can configure a malicious server to return a response with a malformed XML using the Reports integration API, causing an XML External Entity (XXE) attack.
Impact
The vulnerability can be exploited by threat actors who have SDAdmin role to execute an XXE attack and access system files.
Steps to upgrade
Acknowledgements
This vulnerability was reported by minhgalaxy on our bug bounty portal.
If you have any questions or concerns, please contact product support at the email addresses below.
ServiceDesk Plus: support@servicedeskplus.com
ServiceDesk Plus MSP: support@servicedeskplusmsp.com
SupportCenter Plus: support@supportcenterplus.com
AssetExplorer: assetexplorer-support@manageengine.com