PT-2018-5080 · Zoho · Zoho Manageengine Applications Manager

Lukasz Juszczyk

·

Published

2018-06-05

·

Updated

2018-08-07

·

CVE-2016-9490

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ManageEngine Applications Manager versions 12 and 13 before build 13200
Description The issue is related to a Reflected Cross-Site Scripting problem. It affects the parameter LIMIT in the URL path "/DiagAlertAction.do?REQTYPE=AJAX&LIMIT=1233". This URL is accessible without authentication.
Recommendations For ManageEngine Applications Manager versions 12 and 13 before build 13200, update to build 13200 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/DiagAlertAction.do" endpoint and avoiding the use of the LIMIT parameter until the update is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-9490

Affected Products

Zoho Manageengine Applications Manager