Home

Description

An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.

PUBLISHED Reserved 2023-04-07 | Published 2023-08-04 | Updated 2025-05-30 | Assigner mitre




MEDIUM: 4.3CVSS:3.1/AC:L/AV:N/A:N/C:L/I:N/PR:N/S:U/UI:R

References

excellium-services.com/cert-xlm-advisory/CVE-2023-29505

www.manageengine.com/...onitoring/help/read-me-complete.html

www.manageengine.com/itom/advisory/cve-2023-29505.html

cds.thalesgroup.com/en/tcs-cert/CVE-2023-29505

cve.org (CVE-2023-29505)

nvd.nist.gov (CVE-2023-29505)

Download JSON