vendor:
ManageEngine ServiceDesk Plus
by:
Gjoko 'LiquidWorm' Krstic
8.8
CVSS
HIGH
Stored XSS
79
CWE
Product Name: ManageEngine ServiceDesk Plus
Affected Version From: 8.0.0 Build 8013 (Enterprise)
Affected Version To: 8.0.0 Build 8013 (Enterprise)
Patch Exists: YES
Related CWE: N/A
CPE: a:zoho:manageengine_servicedesk_plus:8.0.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows XP Professional SP3 (English), Apache-Coyote/1.1, Java Servlet 2.4, Tomcat-5.0.28/JBoss-3.2.6
2011
ManageEngine ServiceDesk Plus 8.0 Multiple Stored XSS Vulnerabilities
The application suffers from multiple stored XSS vulnerabilities. Input thru several parameters is not sanitized allowing the attacker to execute HTML code into user's browser session on the affected site. Also, couple of HTTP header elements are vulnerable to XSS.
Mitigation:
The vendor has released a patch to address these issues.