Stored XSS Vulnerability in Zoho ManageEngine ServiceDesk Plus MSP
CVE-2023-49943

5.4MEDIUM

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
18 January 2024

What is CVE-2023-49943?

The vulnerability in Zoho ManageEngine ServiceDesk Plus MSP exposes the application to stored cross-site scripting (XSS) attacks. A low-privileged technician can exploit this vulnerability by injecting malicious scripts through task names in the time sheet feature. When other users, including administrators, interact with the tainted task, their browsers may execute the injected scripts, potentially compromising data integrity, user sessions, and overall system security. Organizations using affected versions are advised to assess their risk and apply the necessary updates to mitigate exploitation risks.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.