QID 378343
Date Published: 2023-05-08
QID 378343: Zoho ManageEngine ServiceDesk Plus and ServiceDesk Plus MSP Stored Cross-Site Scripting (XSS) Vulnerability
Zoho ManageEngine ServiceDesk Plus and ServiceDesk Plus MSP are vulnerable to stored cross-site scripting (XSS) vulnerability.
A stored cross-site scripting (XSS) vulnerability allowed any low-privileged user to inject malicious JavaScript when associating a service request from the purchase order details page. The JavaScript is executed when the target user views the Associate Service Requests list view in the Purchase Order details page.
Affected Versions:
ServiceDesk Plus 14102 and below
ServiceDesk Plus MSP 13001 and below
QID Detection Logic (Authenticated):
Windows: Checks for vulnerable version of ManageEngine ServiceDesk Plus and ServiceDesk Plus MSP by reading the version from buildinfo.xml file.
Successful exploitation of this vulnerability may allow an low-privileged attacker to inject malicious JavaScript when associating a service request from the purchase order details page.
- Zoho ManageEngine Security Advisory -
www.manageengine.com/products/service-desk/CVE-2023-23073.html
CVEs related to QID 378343
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Zoho ManageEngine Security Advisory |
|