Stored Cross-Site Scripting Vulnerability in Zoho ManageEngine Applications Manager
CVE-2023-28341
6.1MEDIUM
What is CVE-2023-28341?
A stored cross-site scripting (XSS) vulnerability exists in Zoho ManageEngine Applications Manager version 16340. This flaw allows unauthenticated users to inject malicious JavaScript into the login details page. Exploitation of this vulnerability can lead to the execution of harmful scripts in the context of users' browsers, potentially compromising sensitive information and allowing attackers to execute unauthorized actions on behalf of the users.
References
EPSS Score
86% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved