Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD.
2021-07-01T12:15:07.593
2024-11-21T06:06:16.893
Modified
CVSSv3.1: 5.4 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | zohocorp | manageengine_applications_manager | < 15.1 | Yes |
Application | zohocorp | manageengine_applications_manager | 15.1 | Yes |
Application | zohocorp | manageengine_applications_manager | 15.1 | Yes |
Application | zohocorp | manageengine_applications_manager | 15.1 | Yes |
Application | zohocorp | manageengine_applications_manager | 15.1 | Yes |