vendor:
ManageEngine ADManager Plus
by:
Ismail Tasdelen
7.5
CVSS
HIGH
Cross-site Scripting
79
CWE
Product Name: ManageEngine ADManager Plus
Affected Version From: 6.5.7
Affected Version To: 6.5.7
Patch Exists: NO
Related CWE: N/A
CPE: a:zoho_corp:manageengine_admanager_plus
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
ManageEngine ADManager Plus 6.5.7 – Cross-Site Scripting
Zoho ManageEngine ADManager Plus 6.5.7 allows XSS on the 'Workflow Delegation' 'Requesters' screen.
Mitigation:
Input validation and output encoding should be used to prevent XSS attacks.