Cross Site Scripting Vulnerability in Zoho ManageEngine ServiceDesk Plus
CVE-2023-23077

6.1MEDIUM

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
1 February 2023

What is CVE-2023-23077?

A Cross Site Scripting (XSS) vulnerability exists in Zoho ManageEngine ServiceDesk Plus 13, which can be exploited through a malicious payload in the comment field when adding a new status comment. This type of vulnerability allows attackers to inject harmful scripts, potentially compromising user interactions and data integrity within the application. Users of the affected software should implement the relevant security patches and monitor for unusual activities to mitigate related risks. For detailed information, visit the official documentation provided by Zoho.

References

EPSS Score

20% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.