Stored XSS Vulnerability in Zoho ManageEngine ServiceDesk Plus MSP
CVE-2023-49943
What is CVE-2023-49943?
The vulnerability in Zoho ManageEngine ServiceDesk Plus MSP exposes the application to stored cross-site scripting (XSS) attacks. A low-privileged technician can exploit this vulnerability by injecting malicious scripts through task names in the time sheet feature. When other users, including administrators, interact with the tainted task, their browsers may execute the injected scripts, potentially compromising data integrity, user sessions, and overall system security. Organizations using affected versions are advised to assess their risk and apply the necessary updates to mitigate exploitation risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved