CVE-2019-7424
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/index.jsp" file in the view GET parameter or any of these POST parameters: autorefTime, section, snapshot, viewOpt, viewAll, view, or groupSelName. The latter is related to CVE-2009-3903.
Published
2019-03-21T16:01:13.280
Last Modified
2024-11-21T04:48:12.227
Status
Modified
Source
[email protected]
Severity
CVSSv3.0: 6.1 (MEDIUM)
CVSSv2 Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
- Access Vector: NETWORK
- Access Complexity: MEDIUM
- Authentication: NONE
- Confidentiality Impact: NONE
- Integrity Impact: PARTIAL
- Availability Impact: NONE
Exploitability Score
8.6
Impact Score
2.9
Weaknesses
Affected Vendors & Products
References
-
http://packetstormsecurity.com/files/151585/Zoho-ManageEngine-Netflow-Analyzer-Professional-7.0.0.2-XSS.html
Exploit, Patch, Third Party Advisory, VDB Entry
([email protected])
-
http://seclists.org/fulldisclosure/2019/Feb/29
Exploit, Mailing List, Patch, Third Party Advisory
([email protected])
-
https://www.manageengine.com/products/netflow/?doc
Product, Vendor Advisory
([email protected])
-
http://packetstormsecurity.com/files/151585/Zoho-ManageEngine-Netflow-Analyzer-Professional-7.0.0.2-XSS.html
Exploit, Patch, Third Party Advisory, VDB Entry
(af854a3a-2127-422b-91ae-364da2661108)
-
http://seclists.org/fulldisclosure/2019/Feb/29
Exploit, Mailing List, Patch, Third Party Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
https://www.manageengine.com/products/netflow/?doc
Product, Vendor Advisory
(af854a3a-2127-422b-91ae-364da2661108)