ZOHO ManageEngine Password Manager Pro CVE-2017-17698 Multiple Cross Site Scripting Vulnerabilities
BID:102243
Info
ZOHO ManageEngine Password Manager Pro CVE-2017-17698 Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 102243 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-17698 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 30 2017 12:00AM |
| Updated: | Nov 30 2017 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
ZOHO Corporation ManageEngine Password Manager Pro 9.3 Build 9300 ZOHO Corporation ManageEngine Password Manager Pro 9.2 Build 9200 ZOHO Corporation ManageEngine Password Manager Pro 9.1 Build 9100 ZOHO Corporation ManageEngine Password Manager Pro 9.0 Build 9000 |
| Not Vulnerable: |
ZOHO Corporation ManageEngine Password Manager Pro 9.4 Build 9400 |
Discussion
ZOHO ManageEngine Password Manager Pro CVE-2017-17698 Multiple Cross Site Scripting Vulnerabilities
ZOHO ManageEngine Password Manager Pro is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
ManageEngine Password Manager Pro 9.0 prior to 9.4 are vulnerable.
ZOHO ManageEngine Password Manager Pro is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
ManageEngine Password Manager Pro 9.0 prior to 9.4 are vulnerable.
Exploit / POC
ZOHO ManageEngine Password Manager Pro CVE-2017-17698 Multiple Cross Site Scripting Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
Attackers can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
ZOHO ManageEngine Password Manager Pro CVE-2017-17698 Multiple Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
ZOHO ManageEngine Password Manager Pro CVE-2017-17698 Multiple Cross Site Scripting Vulnerabilities
References:
References:
- ManageEngine Homepage (ManageEngine)
- ManageEngine Password Manager Pro - Release Notes (manageengine)