A blind XML External Entity (XXE) vulnerability exists in...
Moderate severity
Unreviewed
Published
Mar 30, 2023
to the GitHub Advisory Database
•
Updated Apr 13, 2023
Description
Published by the National Vulnerability Database
Mar 30, 2023
Published to the GitHub Advisory Database
Mar 30, 2023
Last updated
Apr 13, 2023
A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability.
References