Cross Site Scripting Vulnerability in Zoho ManageEngine ServiceDesk Plus
CVE-2023-23077
6.1MEDIUM
Key Information:
- Vendor
Zohocorp
- Vendor
- CVE Published:
- 1 February 2023
What is CVE-2023-23077?
A Cross Site Scripting (XSS) vulnerability exists in Zoho ManageEngine ServiceDesk Plus 13, which can be exploited through a malicious payload in the comment field when adding a new status comment. This type of vulnerability allows attackers to inject harmful scripts, potentially compromising user interactions and data integrity within the application. Users of the affected software should implement the relevant security patches and monitor for unusual activities to mitigate related risks. For detailed information, visit the official documentation provided by Zoho.