Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.
| Software | From | Fixed in |
|---|---|---|
| zohocorp / manageengine_applications_manager | - | 16.3 |
| zohocorp / manageengine_applications_manager | 16.3-build16310 | 16.3-build16310.x |
| zohocorp / manageengine_applications_manager | 16.3-build16320 | 16.3-build16320.x |
| zohocorp / manageengine_applications_manager | 16.3-build16300 | 16.3-build16300.x |