vendor:
ManageEngine AssetExplorer
by:
Ismail Tasdelen
7.5
CVSS
HIGH
Cross-Site Scripting
79
CWE
Product Name: ManageEngine AssetExplorer
Affected Version From: 6.2.0
Affected Version To: 6.2.0
Patch Exists: YES
Related CWE: N/A
CPE: a:zoho:manageengine_assetexplorer:6.2.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
ManageEngine AssetExplorer 6.2.0 – Cross-Site Scripting
In Zoho ManageEngine AssetExplorer, a Stored XSS vulnerability was discovered in the 6.2.0 version via the /AssetDef.do ciName or assetName parameter.
Mitigation:
Input validation should be used to prevent XSS attacks.