Resource exhaustion in Zoho ManageEngine ServiceDesk Plus - CVE-2023-26601
Published: January 25, 2023 / Updated: March 9, 2023
Zoho ManageEngine ServiceDesk Plus
Detailed vulnerability description
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in the images upload feature (ImageUploadServlet). A remote user can upload unlimited number of images, consume all available disk space and perform a denial of service (DoS) attack.