5.4

CVE-2023-38331

Zoho ManageEngine Support Center Plus 14001 and below is vulnerable to stored XSS in the products module.

Data is provided by the National Vulnerability Database (NVD)
ZohocorpManageengine Supportcenter Plus Version8.0 Update8015
ZohocorpManageengine Supportcenter Plus Version8.1 Update8100
ZohocorpManageengine Supportcenter Plus Version8.1 Update8101
ZohocorpManageengine Supportcenter Plus Version8.1 Update8102
ZohocorpManageengine Supportcenter Plus Version8.1 Update8117
ZohocorpManageengine Supportcenter Plus Version8.1 Update8118
ZohocorpManageengine Supportcenter Plus Version8.1 Update8119
ZohocorpManageengine Supportcenter Plus Version8.1 Update8121
ZohocorpManageengine Supportcenter Plus Version11.0 Update11000
ZohocorpManageengine Supportcenter Plus Version11.0 Update11024
ZohocorpManageengine Supportcenter Plus Version11.0 Update11026
ZohocorpManageengine Supportcenter Plus Version11.0 Update11027
ZohocorpManageengine Supportcenter Plus Version14.0 Update14000
ZohocorpManageengine Supportcenter Plus Version14.0 Update14001
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.79% 0.855
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.