6.1

CVE-2018-20485

Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature.

Data is provided by the National Vulnerability Database (NVD)
ZohocorpManageengine Adselfservice Plus Version4.5 Update4510
ZohocorpManageengine Adselfservice Plus Version4.5 Update4511
ZohocorpManageengine Adselfservice Plus Version4.5 Update4520
ZohocorpManageengine Adselfservice Plus Version4.5 Update4522
ZohocorpManageengine Adselfservice Plus Version4.5 Update4531
ZohocorpManageengine Adselfservice Plus Version4.5 Update4540
ZohocorpManageengine Adselfservice Plus Version4.5 Update4543
ZohocorpManageengine Adselfservice Plus Version4.5 Update4544
ZohocorpManageengine Adselfservice Plus Version4.5 Update4550
ZohocorpManageengine Adselfservice Plus Version4.5 Update4560
ZohocorpManageengine Adselfservice Plus Version4.5 Update4570
ZohocorpManageengine Adselfservice Plus Version4.5 Update4571
ZohocorpManageengine Adselfservice Plus Version4.5 Update4572
ZohocorpManageengine Adselfservice Plus Version4.5 Update4580
ZohocorpManageengine Adselfservice Plus Version4.5 Update4590
ZohocorpManageengine Adselfservice Plus Version4.5 Update4591
ZohocorpManageengine Adselfservice Plus Version4.5 Update4592
ZohocorpManageengine Adselfservice Plus Version5.0 Update5000
ZohocorpManageengine Adselfservice Plus Version5.0 Update5001
ZohocorpManageengine Adselfservice Plus Version5.0 Update5002
ZohocorpManageengine Adselfservice Plus Version5.0 Update5010
ZohocorpManageengine Adselfservice Plus Version5.0 Update5011
ZohocorpManageengine Adselfservice Plus Version5.0 Update5020
ZohocorpManageengine Adselfservice Plus Version5.0 Update5021
ZohocorpManageengine Adselfservice Plus Version5.0 Update5022
ZohocorpManageengine Adselfservice Plus Version5.0 Update5030
ZohocorpManageengine Adselfservice Plus Version5.0 Update5032
ZohocorpManageengine Adselfservice Plus Version5.0 Update5040
ZohocorpManageengine Adselfservice Plus Version5.0 Update5041
ZohocorpManageengine Adselfservice Plus Version5.1 Update5100
ZohocorpManageengine Adselfservice Plus Version5.1 Update5101
ZohocorpManageengine Adselfservice Plus Version5.1 Update5102
ZohocorpManageengine Adselfservice Plus Version5.1 Update5103
ZohocorpManageengine Adselfservice Plus Version5.1 Update5104
ZohocorpManageengine Adselfservice Plus Version5.1 Update5105
ZohocorpManageengine Adselfservice Plus Version5.1 Update5106
ZohocorpManageengine Adselfservice Plus Version5.1 Update5107
ZohocorpManageengine Adselfservice Plus Version5.1 Update5108
ZohocorpManageengine Adselfservice Plus Version5.1 Update5109
ZohocorpManageengine Adselfservice Plus Version5.1 Update5110
ZohocorpManageengine Adselfservice Plus Version5.1 Update5111
ZohocorpManageengine Adselfservice Plus Version5.1 Update5112
ZohocorpManageengine Adselfservice Plus Version5.1 Update5113
ZohocorpManageengine Adselfservice Plus Version5.1 Update5114
ZohocorpManageengine Adselfservice Plus Version5.1 Update5115
ZohocorpManageengine Adselfservice Plus Version5.2 Update5200
ZohocorpManageengine Adselfservice Plus Version5.2 Update5201
ZohocorpManageengine Adselfservice Plus Version5.2 Update5202
ZohocorpManageengine Adselfservice Plus Version5.2 Update5203
ZohocorpManageengine Adselfservice Plus Version5.2 Update5204
ZohocorpManageengine Adselfservice Plus Version5.2 Update5205
ZohocorpManageengine Adselfservice Plus Version5.2 Update5206
ZohocorpManageengine Adselfservice Plus Version5.2 Update5207
ZohocorpManageengine Adselfservice Plus Version5.3 Update5300
ZohocorpManageengine Adselfservice Plus Version5.3 Update5301
ZohocorpManageengine Adselfservice Plus Version5.3 Update5302
ZohocorpManageengine Adselfservice Plus Version5.3 Update5303
ZohocorpManageengine Adselfservice Plus Version5.3 Update5304
ZohocorpManageengine Adselfservice Plus Version5.3 Update5305
ZohocorpManageengine Adselfservice Plus Version5.3 Update5306
ZohocorpManageengine Adselfservice Plus Version5.3 Update5307
ZohocorpManageengine Adselfservice Plus Version5.3 Update5308
ZohocorpManageengine Adselfservice Plus Version5.3 Update5309
ZohocorpManageengine Adselfservice Plus Version5.3 Update5310
ZohocorpManageengine Adselfservice Plus Version5.3 Update5311
ZohocorpManageengine Adselfservice Plus Version5.3 Update5312
ZohocorpManageengine Adselfservice Plus Version5.3 Update5313
ZohocorpManageengine Adselfservice Plus Version5.3 Update5314
ZohocorpManageengine Adselfservice Plus Version5.3 Update5315
ZohocorpManageengine Adselfservice Plus Version5.3 Update5316
ZohocorpManageengine Adselfservice Plus Version5.3 Update5317
ZohocorpManageengine Adselfservice Plus Version5.3 Update5318
ZohocorpManageengine Adselfservice Plus Version5.3 Update5319
ZohocorpManageengine Adselfservice Plus Version5.3 Update5320
ZohocorpManageengine Adselfservice Plus Version5.3 Update5321
ZohocorpManageengine Adselfservice Plus Version5.3 Update5322
ZohocorpManageengine Adselfservice Plus Version5.3 Update5323
ZohocorpManageengine Adselfservice Plus Version5.3 Update5324
ZohocorpManageengine Adselfservice Plus Version5.3 Update5325
ZohocorpManageengine Adselfservice Plus Version5.3 Update5326
ZohocorpManageengine Adselfservice Plus Version5.3 Update5327
ZohocorpManageengine Adselfservice Plus Version5.3 Update5328
ZohocorpManageengine Adselfservice Plus Version5.3 Update5329
ZohocorpManageengine Adselfservice Plus Version5.3 Update5330
ZohocorpManageengine Adselfservice Plus Version5.4 Update5400
ZohocorpManageengine Adselfservice Plus Version5.5 Update5500
ZohocorpManageengine Adselfservice Plus Version5.5 Update5501
ZohocorpManageengine Adselfservice Plus Version5.5 Update5502
ZohocorpManageengine Adselfservice Plus Version5.5 Update5503
ZohocorpManageengine Adselfservice Plus Version5.5 Update5504
ZohocorpManageengine Adselfservice Plus Version5.5 Update5505
ZohocorpManageengine Adselfservice Plus Version5.5 Update5506
ZohocorpManageengine Adselfservice Plus Version5.5 Update5507
ZohocorpManageengine Adselfservice Plus Version5.5 Update5508
ZohocorpManageengine Adselfservice Plus Version5.5 Update5509
ZohocorpManageengine Adselfservice Plus Version5.5 Update5510
ZohocorpManageengine Adselfservice Plus Version5.5 Update5511
ZohocorpManageengine Adselfservice Plus Version5.5 Update5512
ZohocorpManageengine Adselfservice Plus Version5.5 Update5513
ZohocorpManageengine Adselfservice Plus Version5.5 Update5514
ZohocorpManageengine Adselfservice Plus Version5.5 Update5515
ZohocorpManageengine Adselfservice Plus Version5.5 Update5516
ZohocorpManageengine Adselfservice Plus Version5.5 Update5517
ZohocorpManageengine Adselfservice Plus Version5.5 Update5518
ZohocorpManageengine Adselfservice Plus Version5.5 Update5519
ZohocorpManageengine Adselfservice Plus Version5.5 Update5520
ZohocorpManageengine Adselfservice Plus Version5.5 Update5521
ZohocorpManageengine Adselfservice Plus Version5.6 Update5600
ZohocorpManageengine Adselfservice Plus Version5.6 Update5601
ZohocorpManageengine Adselfservice Plus Version5.6 Update5602
ZohocorpManageengine Adselfservice Plus Version5.6 Update5603
ZohocorpManageengine Adselfservice Plus Version5.6 Update5604
ZohocorpManageengine Adselfservice Plus Version5.6 Update5605
ZohocorpManageengine Adselfservice Plus Version5.6 Update5606
ZohocorpManageengine Adselfservice Plus Version5.6 Update5607
ZohocorpManageengine Adselfservice Plus Version5.7 Update5702
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.59% 0.679
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.