QID 378342
Date Published: 2023-04-06
QID 378342: Zoho ManageEngine ServiceDesk Plus Stored Cross-Site Scripting (XSS) Vulnerability
Zoho ManageEngine ServiceDesk Plus is vulnerable to stored cross-site scripting (XSS) vulnerability.
A stored cross-site scripting (XSS) vulnerability allowed users with the Admin role to inject a malicious JavaScript under the Advanced Portal configurations. The script is executed when a user views the product tour or the product tour preview.
Affected Versions:
ServiceDesk Plus 14103 and below
QID Detection Logic (Authenticated):
Windows: Checks for vulnerable version of ManageEngine ServiceDesk Plus by reading the version from buildinfo.xml file.
Successful exploitation of this vulnerability may allow an attacker with the Admin role to inject a malicious JavaScript under the Advanced Portal configurations.
Solution
Vendor has released patches addressing the vulnerability. For more information please refer to Zoho ManageEngine Security Advisory
Vendor References
- Zoho ManageEngine Security Advisory -
www.manageengine.com/products/service-desk/CVE-2023-23074.html
CVEs related to QID 378342
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Zoho ManageEngine Security Advisory |
|