HTML Injection Vulnerability in ManageEngine Remote Access Plus by Zoho
CVE-2019-16268
4.8MEDIUM
What is CVE-2019-16268?
The ManageEngine Remote Access Plus, version 10.0.259, is subject to an HTML injection vulnerability allowing attackers to manipulate the application through the Description field in the Admin - User Administration interface. This flaw could enable unauthorized actions by injecting malicious HTML into user profiles, potentially leading to data theft or service disruption. Proper input validation and sanitization measures are crucial to mitigate this issue and protect user data from exploitation.