HTML Injection Vulnerability in Zoho ManageEngine Desktop Central
CVE-2019-16962

5.4MEDIUM

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
6 January 2021

What is CVE-2019-16962?

Zoho ManageEngine Desktop Central, version 10.0.430, is susceptible to an HTML injection vulnerability that arises from improperly sanitized input in the Report Name field of a New Custom Report feature. An attacker could exploit this vulnerability to inject malicious HTML code, potentially compromising the integrity of the application and affecting users by enabling unauthorized actions.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.