6.1

CVE-2025-9787

Stored XSS

Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Applications Manager Version >= 17.4 < 17.7
Zohocorp ≫ Manageengine Applications Manager Version 17.3 Update build173300
Zohocorp ≫ Manageengine Applications Manager Version 17.3 Update build173301
Zohocorp ≫ Manageengine Applications Manager Version 17.3 Update build173302
Zohocorp ≫ Manageengine Applications Manager Version 17.3 Update build173303
Zohocorp ≫ Manageengine Applications Manager Version 17.3 Update build173304
Zohocorp ≫ Manageengine Applications Manager Version 17.7 Update -
Zohocorp ≫ Manageengine Applications Manager Version 17.7 Update build177000
Zohocorp ≫ Manageengine Applications Manager Version 17.7 Update build177100
Zohocorp ≫ Manageengine Applications Manager Version 17.7 Update build177200
Zohocorp ≫ Manageengine Applications Manager Version 17.7 Update build177201
Zohocorp ≫ Manageengine Applications Manager Version 17.7 Update build177202
Zohocorp ≫ Manageengine Applications Manager Version 17.7 Update build177203
Zohocorp ≫ Manageengine Applications Manager Version 17.7 Update build177204
Zohocorp ≫ Manageengine Applications Manager Version 17.7 Update build177300
Zohocorp ≫ Manageengine Applications Manager Version 17.7 Update build177400
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.08% 0.622
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
0fc0942c-577d-436f-ae8e-945763c79b02 6.1 0.9 5.2
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2025-9787.html
Patch
Vendor Advisory