Cross-Site Scripting Vulnerability in ManageEngine OpStor by Zoho
CVE-2014-2670
Currently unrated
What is CVE-2014-2670?
A cross-site scripting (XSS) vulnerability exists in the Properties.do component of Zoho's ManageEngine OpStor before build 8500. This vulnerability allows remote authenticated users to inject malicious web scripts or HTML into the application through the 'name' parameter. It poses a risk as attackers can exploit this flaw to execute arbitrary scripts in the context of the user's session, potentially leading to data theft, session hijacking, or other malicious activities. Addressing and patching this vulnerability is essential to maintain the security integrity of web applications.