Zoho ManageEngine OpManager CVE-2018-19288 Cross Site Scripting Vulnerability
BID:105960
CVE-2018-19288 |Info
Zoho ManageEngine OpManager CVE-2018-19288 Cross Site Scripting Vulnerability
| Bugtraq ID: | 105960 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-19288 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 13 2018 12:00AM |
| Updated: | Nov 13 2018 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Zohocorp Manageengine Opmanager 9.4 Zohocorp Manageengine Opmanager 9.2 Zohocorp Manageengine Opmanager 9.1 Zohocorp Manageengine Opmanager 9.0 Zohocorp Manageengine Opmanager 8.8 Zohocorp Manageengine Opmanager 12.3 Zohocorp Manageengine Opmanager 11.6 build 11600 Zohocorp Manageengine Opmanager 11.6 Zohocorp Manageengine Opmanager 11.5 Build 11600 Zohocorp Manageengine Opmanager 11.5 Build 11500 Zohocorp Manageengine Opmanager 11.5 Zohocorp Manageengine Opmanager 11.4 Zohocorp Manageengine Opmanager 11.3 Zohocorp Manageengine Opmanager 11.2 Zohocorp Manageengine Opmanager 11.1 Zohocorp Manageengine Opmanager 11.0 Zohocorp Manageengine Opmanager 10.2 Zohocorp Manageengine Opmanager 10.1 Zohocorp Manageengine Opmanager 10.0 |
| Not Vulnerable: |
Zohocorp Manageengine Opmanager 12.3 Build 123223 |
Discussion
Zoho ManageEngine OpManager CVE-2018-19288 Cross Site Scripting Vulnerability
Zoho ManageEngine OpManager is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to perform unauthorized actions such as reading, modifying, or deleting content, or inject malicious content.
Versions prior to Zoho ManageEngine OpManager 12.3 Build 123223 are vulnerable.
Zoho ManageEngine OpManager is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to perform unauthorized actions such as reading, modifying, or deleting content, or inject malicious content.
Versions prior to Zoho ManageEngine OpManager 12.3 Build 123223 are vulnerable.
References
Zoho ManageEngine OpManager CVE-2018-19288 Cross Site Scripting Vulnerability
References:
References:
- ManageEngine OpManager Homepage (AdventNet)
- OpManager Change Log (Zoho)