6.1

CVE-2025-9787

Stored XSS

Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZohocorpManageengine Applications Manager Version >= 17.4 < 17.7
ZohocorpManageengine Applications Manager Version17.3 Updatebuild173300
ZohocorpManageengine Applications Manager Version17.3 Updatebuild173301
ZohocorpManageengine Applications Manager Version17.3 Updatebuild173302
ZohocorpManageengine Applications Manager Version17.3 Updatebuild173303
ZohocorpManageengine Applications Manager Version17.3 Updatebuild173304
ZohocorpManageengine Applications Manager Version17.7 Updatebuild177000
ZohocorpManageengine Applications Manager Version17.7 Updatebuild177100
ZohocorpManageengine Applications Manager Version17.7 Updatebuild177200
ZohocorpManageengine Applications Manager Version17.7 Updatebuild177201
ZohocorpManageengine Applications Manager Version17.7 Updatebuild177202
ZohocorpManageengine Applications Manager Version17.7 Updatebuild177203
ZohocorpManageengine Applications Manager Version17.7 Updatebuild177204
ZohocorpManageengine Applications Manager Version17.7 Updatebuild177300
ZohocorpManageengine Applications Manager Version17.7 Updatebuild177400
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.91% 0.551
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
0fc0942c-577d-436f-ae8e-945763c79b02 6.1 0.9 5.2
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2025-9787.html
Patch
Vendor Advisory