PT-2021-8996 · Zoho · Zoho Manageengine Desktop Central

Published

2021-01-06

·

Updated

2021-07-21

·

CVE-2019-16962

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine Desktop Central version 10.0.430
Description The issue allows HTML injection via a modified Report Name in a New Custom Report. This can occur when a user creates a new custom report and modifies the report name to include malicious HTML content.
Recommendations For Zoho ManageEngine Desktop Central version 10.0.430, consider validating and sanitizing user-input data for the Report Name field in New Custom Reports to prevent HTML injection attacks. As a temporary workaround, restrict the ability to create new custom reports or modify existing report names until a fix is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-16962

Affected Products

Zoho Manageengine Desktop Central