QID 378342

Date Published: 2023-04-06

QID 378342: Zoho ManageEngine ServiceDesk Plus Stored Cross-Site Scripting (XSS) Vulnerability

Zoho ManageEngine ServiceDesk Plus is vulnerable to stored cross-site scripting (XSS) vulnerability.

A stored cross-site scripting (XSS) vulnerability allowed users with the Admin role to inject a malicious JavaScript under the Advanced Portal configurations. The script is executed when a user views the product tour or the product tour preview.

Affected Versions:
ServiceDesk Plus 14103 and below

QID Detection Logic (Authenticated):
Windows: Checks for vulnerable version of ManageEngine ServiceDesk Plus by reading the version from buildinfo.xml file.

Successful exploitation of this vulnerability may allow an attacker with the Admin role to inject a malicious JavaScript under the Advanced Portal configurations.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Vendor has released patches addressing the vulnerability. For more information please refer to Zoho ManageEngine Security Advisory

    Vendor References

    CVEs related to QID 378342

    Software Advisories
    Advisory ID Software Component Link
    Zoho ManageEngine Security Advisory URL Logo www.manageengine.com/products/service-desk/CVE-2023-23074.html