DOM XSS Vulnerability in Zoho ManageEngine Applications Manager
CVE-2023-29442
6.1MEDIUM
What is CVE-2023-29442?
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in Zoho ManageEngine Applications Manager prior to version 16400. The flaw arises from improper handling of user input in the proxy.html component. An attacker can exploit this vulnerability to inject malicious scripts into the web application, which may lead to unauthorized access to sensitive user data or perform actions on behalf of the user without their consent.