getAsDoc. This manipulation causes xml external entity reference.
This vulnerability is handled as CVE-2022-40771. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
Intelligence View
⚡ tsecurity.de Intelligence
CVE-2022-40771 | Zoho ManageEngine ServiceDesk Plus getAsDoc xml external entity reference (ZDI-22-1612 / EUVD-2022-44037)
Reagiere als Erste:r — dein Feedback zählt!
A vulnerability identified as problematic has been detected in Zoho ManageEngine ServiceDesk Plus. The impacted element is the function
SOCIAL SHARE CARD GENERATOR