High severity7.5NVD Advisory· Published Nov 6, 2018· Updated Jun 17, 2026
CVE-2018-18980
CVE-2018-18980
Description
An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the RequestXML parameter in a /devices/ProcessRequest.do GET request. For example, the attacker can trigger the transmission of local files to an arbitrary remote FTP server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:a:zohocorp:manageengine_network_configuration_manager:*:*:*:*:*:*:*:*Range: <12.3.214
- cpe:2.3:a:zohocorp:manageengine_opmanager:*:*:*:*:*:*:*:*Range: <12.3.214
- Range: <12.3.214
Patches
Vulnerability mechanics
References
2- github.com/x-f1v3/ForCve/issues/5nvdExploitThird Party Advisory
- www.manageengine.com/network-monitoring/help/read-me.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.