vendor:
ServiceDesk Plus
by:
Narendra Shinde
5.5
CVSS
MEDIUM
Improper Neutralization of Input during Web Page Generation ('Cross-site Scripting')
79
CWE
Product Name: ServiceDesk Plus
Affected Version From: 8.0 Build 8013
Affected Version To: 8.0 Build 8013
Patch Exists: N/A
Related CWE: N/A
CPE: a:manageengine:servicedesk_plus:8.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2011
ManageEngine ServiceDesk Plus 8.0 Build 8013 Multiple Persistence Cross Site Scripting Vulnerabilities
ServiceDesk Plus version 8.0 Build 8013 is prone to multiple persistent cross-site scripting vulnerabilities as the user-supplied input received via certain parameters is not properly sanitized. This can be exploited by submitting specially crafted input to the affected software. Successful exploitation could allow the attacker to execute arbitrary script code within the user's browser sesssion in the context of the affected site.
Mitigation:
N/A