Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-18980

An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the RequestXML parameter in a /devices/ProcessRequest.do GET request. For example, the attacker can trigger the transmission of local files to an arbitrary remote FTP server.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.367
EPSS Ranking 96.9%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2018-18980


Contact Us

Shodan ® - All rights reserved