PT-2018-13800 · Zoho · Zoho Manageengine Supportcenter Plus
Publicado
2018-09-21
·
Atualizado
2018-11-09
·
CVE-2018-16965
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Zoho ManageEngine SupportCenter Plus versions prior to 8.1 Build 8109
Description
The issue concerns HTML Injection and Stored XSS. It can be exploited via the /ServiceContractDef.do
contractName parameter.Recommendations
For versions prior to 8.1 Build 8109, update to version 8.1 Build 8109 or later to resolve the issue. As a temporary workaround, consider restricting access to the /ServiceContractDef.do endpoint or avoiding the use of the
contractName parameter until the update is applied.Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Zoho Manageengine Supportcenter Plus