QID 378335
Date Published: 2023-04-06
QID 378335: Zoho ManageEngine ServiceDesk Plus Stored Cross-Site Scripting (XSS) Vulnerability
Zoho ManageEngine ServiceDesk Plus is vulnerable to stored cross-site scripting (XSS) vulnerability.
A stored cross-site scripting (XSS) vulnerability allowed users to inject a malicious JavaScript in the Add Release page. The script gets executed when a user views the Release Details page.
Affected Versions:
ServiceDesk Plus 14002 and below
QID Detection Logic (Authenticated):
Windows: Checks for vulnerable version of ManageEngine ServiceDesk Plus by reading the version from buildinfo.xml file.
Successful exploitation of this vulnerability may allow an attacker to execute arbitrary JavaScript code and steal sensitive data of the targeted user.
Solution
Vendor has released patches addressing the vulnerability. For more information please refer to Zoho ManageEngine Security Advisory
Vendor References
- Zoho ManageEngine Security Advisory -
www.manageengine.com/products/service-desk/CVE-2023-23077.html
CVEs related to QID 378335
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Zoho ManageEngine Security Advisory |
|