6.1

CVE-2023-23075

Cross Site Scripting (XSS) vulnerability in Zoho Asset Explorer 6.9 via the credential name when creating a new Assets Workstation.

Data is provided by the National Vulnerability Database (NVD)
ZohocorpManageengine Assetexplorer Version6.9 Update-
ZohocorpManageengine Assetexplorer Version6.9 Update6900
ZohocorpManageengine Assetexplorer Version6.9 Update6901
ZohocorpManageengine Assetexplorer Version6.9 Update6902
ZohocorpManageengine Assetexplorer Version6.9 Update6903
ZohocorpManageengine Assetexplorer Version6.9 Update6904
ZohocorpManageengine Assetexplorer Version6.9 Update6905
ZohocorpManageengine Assetexplorer Version6.9 Update6906
ZohocorpManageengine Assetexplorer Version6.9 Update6907
ZohocorpManageengine Assetexplorer Version6.9 Update6908
ZohocorpManageengine Assetexplorer Version6.9 Update6909
ZohocorpManageengine Assetexplorer Version6.9 Update6950
ZohocorpManageengine Assetexplorer Version6.9 Update6951
ZohocorpManageengine Assetexplorer Version6.9 Update6952
ZohocorpManageengine Assetexplorer Version6.9 Update6953
ZohocorpManageengine Assetexplorer Version6.9 Update6954
ZohocorpManageengine Assetexplorer Version6.9 Update6955
ZohocorpManageengine Assetexplorer Version6.9 Update6956
ZohocorpManageengine Assetexplorer Version6.9 Update6957
ZohocorpManageengine Assetexplorer Version6.9 Update6970
ZohocorpManageengine Assetexplorer Version6.9 Update6971
ZohocorpManageengine Assetexplorer Version6.9 Update6972
ZohocorpManageengine Assetexplorer Version6.9 Update6973
ZohocorpManageengine Assetexplorer Version6.9 Update6974
ZohocorpManageengine Assetexplorer Version6.9 Update6975
ZohocorpManageengine Assetexplorer Version6.9 Update6976
ZohocorpManageengine Assetexplorer Version6.9 Update6977
ZohocorpManageengine Assetexplorer Version6.9 Update6978
ZohocorpManageengine Assetexplorer Version6.9 Update6979
ZohocorpManageengine Assetexplorer Version6.9 Update6980
ZohocorpManageengine Assetexplorer Version6.9 Update6981
ZohocorpManageengine Assetexplorer Version6.9 Update6982
ZohocorpManageengine Assetexplorer Version6.9 Update6983
ZohocorpManageengine Assetexplorer Version6.9 Update6984
ZohocorpManageengine Assetexplorer Version6.9 Update6985
ZohocorpManageengine Assetexplorer Version6.9 Update6986
ZohocorpManageengine Assetexplorer Version6.9 Update6987
ZohocorpManageengine Assetexplorer Version6.9 Update6988
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 5.95% 0.903
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.