PT-2018-13800 · Zoho · Zoho Manageengine Supportcenter Plus

Publicado

2018-09-21

·

Atualizado

2018-11-09

·

CVE-2018-16965

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine SupportCenter Plus versions prior to 8.1 Build 8109
Description The issue concerns HTML Injection and Stored XSS. It can be exploited via the /ServiceContractDef.do contractName parameter.
Recommendations For versions prior to 8.1 Build 8109, update to version 8.1 Build 8109 or later to resolve the issue. As a temporary workaround, consider restricting access to the /ServiceContractDef.do endpoint or avoiding the use of the contractName parameter until the update is applied.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-16965

Produtos afetados

Zoho Manageengine Supportcenter Plus