Stored Cross-Site Scripting Vulnerability in Zoho ManageEngine Applications Manager
CVE-2023-28341

6.1MEDIUM

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
11 April 2023

What is CVE-2023-28341?

A stored cross-site scripting (XSS) vulnerability exists in Zoho ManageEngine Applications Manager version 16340. This flaw allows unauthenticated users to inject malicious JavaScript into the login details page. Exploitation of this vulnerability can lead to the execution of harmful scripts in the context of users' browsers, potentially compromising sensitive information and allowing attackers to execute unauthorized actions on behalf of the users.

References

EPSS Score

86% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.