HTML Injection Vulnerability in Zoho ManageEngine Desktop Central
CVE-2019-16962
5.4MEDIUM
What is CVE-2019-16962?
Zoho ManageEngine Desktop Central, version 10.0.430, is susceptible to an HTML injection vulnerability that arises from improperly sanitized input in the Report Name field of a New Custom Report feature. An attacker could exploit this vulnerability to inject malicious HTML code, potentially compromising the integrity of the application and affecting users by enabling unauthorized actions.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved