Resource exhaustion in Zoho ManageEngine ServiceDesk Plus - CVE-2023-26601
Published: January 25, 2023 / Updated: March 9, 2023
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in the images upload feature (ImageUploadServlet). A remote user can upload unlimited number of images, consume all available disk space and perform a denial of service (DoS) attack.
Affected software
Zoho ManageEngine ServiceDesk Plus MSP
How to mitigate CVE-2023-26601
Zoho ManageEngine ServiceDesk Plus MSP - update to 14001