QID 378334

Date Published: 2023-05-08

QID 378334: Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and AssetExplorer Stored Cross-Site Scripting (XSS) Vulnerability

Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and AssetExplorer are vulnerable to stored cross-site scripting (XSS) vulnerability.

Stored Cross-Site Scripting (XSS) vulnerability allowed users to inject a malicious JavaScript in the asset details page. The script is executed when a user views the asset page.

Affected Versions:
ServiceDesk Plus 14102 and below
ServiceDesk Plus MSP 13004 and below
AssetExplorer 6986 and below

QID Detection Logic (Authenticated):
Windows: Checks for vulnerable version of ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and AssetExplorer by reading the version from buildinfo.xml file.

Successful exploitation of this vulnerability may allow an attacker to execute arbitrary JavaScript code and steal sensitive data of the targeted user.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Vendor has released patches addressing the vulnerability. For more information please refer to Zoho ManageEngine Security Advisory

    Vendor References

    CVEs related to QID 378334

    Software Advisories
    Advisory ID Software Component Link
    Zoho ManageEngine Security Advisory URL Logo www.manageengine.com/products/service-desk/CVE-2023-23078.html