6.1

CVE-2019-11676

The user defined DNS name in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to stored XSS attacks.

Data is provided by the National Vulnerability Database (NVD)
ZohocorpManageengine Firewall Analyzer Version7.2 Update7020
ZohocorpManageengine Firewall Analyzer Version7.2 Update7021
ZohocorpManageengine Firewall Analyzer Version7.4 Update7400
ZohocorpManageengine Firewall Analyzer Version7.6 Update7600
ZohocorpManageengine Firewall Analyzer Version8.0 Update8000
ZohocorpManageengine Firewall Analyzer Version8.1 Update8110
ZohocorpManageengine Firewall Analyzer Version8.3 Update8300
ZohocorpManageengine Firewall Analyzer Version8.5 Update8500
ZohocorpManageengine Firewall Analyzer Version12.0 Update12000
ZohocorpManageengine Firewall Analyzer Version12.2 Update12200
ZohocorpManageengine Firewall Analyzer Version12.3 Update12300
ZohocorpManageengine Firewall Analyzer Version12.3 Update123008
ZohocorpManageengine Firewall Analyzer Version12.3 Update123027
ZohocorpManageengine Firewall Analyzer Version12.3 Update123045
ZohocorpManageengine Firewall Analyzer Version12.3 Update123057
ZohocorpManageengine Firewall Analyzer Version12.3 Update123064
ZohocorpManageengine Firewall Analyzer Version12.3 Update123070
ZohocorpManageengine Firewall Analyzer Version12.3 Update123083
ZohocorpManageengine Firewall Analyzer Version12.3 Update123092
ZohocorpManageengine Firewall Analyzer Version12.3 Update123126
ZohocorpManageengine Firewall Analyzer Version12.3 Update123129
ZohocorpManageengine Firewall Analyzer Version12.3 Update123137
ZohocorpManageengine Firewall Analyzer Version12.3 Update123151
ZohocorpManageengine Firewall Analyzer Version12.3 Update123156
ZohocorpManageengine Firewall Analyzer Version12.3 Update123164
ZohocorpManageengine Firewall Analyzer Version12.3 Update123169
ZohocorpManageengine Firewall Analyzer Version12.3 Update123177
ZohocorpManageengine Firewall Analyzer Version12.3 Update123182
ZohocorpManageengine Firewall Analyzer Version12.3 Update123185
ZohocorpManageengine Firewall Analyzer Version12.3 Update123186
ZohocorpManageengine Firewall Analyzer Version12.3 Update123194
ZohocorpManageengine Firewall Analyzer Version12.3 Update123197
ZohocorpManageengine Firewall Analyzer Version12.3 Update123208
ZohocorpManageengine Firewall Analyzer Version12.3 Update123218
ZohocorpManageengine Firewall Analyzer Version12.3 Update123222
ZohocorpManageengine Firewall Analyzer Version12.3 Update123223
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.35% 0.843
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.