6.1
CVE-2025-9787
- EPSS 0.34%
- Veröffentlicht 18.12.2025 14:14:52
- Zuletzt bearbeitet 29.01.2026 19:22:37
- Quelle 0fc0942c-577d-436f-ae8e-945763
- CVE-Watchlists
- Unerledigt
Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Applications Manager Version >= 17.4 < 17.7
Zohocorp ≫ Manageengine Applications Manager Version17.3 Updatebuild173300
Zohocorp ≫ Manageengine Applications Manager Version17.3 Updatebuild173301
Zohocorp ≫ Manageengine Applications Manager Version17.3 Updatebuild173302
Zohocorp ≫ Manageengine Applications Manager Version17.3 Updatebuild173303
Zohocorp ≫ Manageengine Applications Manager Version17.3 Updatebuild173304
Zohocorp ≫ Manageengine Applications Manager Version17.7 Update-
Zohocorp ≫ Manageengine Applications Manager Version17.7 Updatebuild177000
Zohocorp ≫ Manageengine Applications Manager Version17.7 Updatebuild177100
Zohocorp ≫ Manageengine Applications Manager Version17.7 Updatebuild177200
Zohocorp ≫ Manageengine Applications Manager Version17.7 Updatebuild177201
Zohocorp ≫ Manageengine Applications Manager Version17.7 Updatebuild177202
Zohocorp ≫ Manageengine Applications Manager Version17.7 Updatebuild177203
Zohocorp ≫ Manageengine Applications Manager Version17.7 Updatebuild177204
Zohocorp ≫ Manageengine Applications Manager Version17.7 Updatebuild177300
Zohocorp ≫ Manageengine Applications Manager Version17.7 Updatebuild177400
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.34% | 0.559 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 0fc0942c-577d-436f-ae8e-945763c79b02 | 6.1 | 0.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.