Known vulnerabilities in ManageEngine RecoveryManager Plus
Vendor:
Zoho Corporation
Software:
ManageEngine RecoveryManager Plus
Software CPE:
cpe:2.3:a:zohocorp:manageengine_recovery_manager_plus:*:*:*:*:*:*:*:*
Website:
https://www.zohocorp.com/index.html
Total vulnerabilities:
2
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Breakdown by Severity Chart
Vulnerabilities (2)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU83444 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2023-48646 |
CWE-78 | Low | 6070 | 22.11.2023 |
SB2023112249 |
||
| #VU14717 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2018-9163 |
CWE-79 | Low | - | 02.04.2018 |
SB2018040208 |