vendor:
Asset Explorer
by:
5.5
CVSS
MEDIUM
Cross site scripting
79
CWE
Product Name: Asset Explorer
Affected Version From: 6.1.2000
Affected Version To: 6.1.2000
Patch Exists: NO
Related CWE: CVE-2015-2169
CPE:
Platforms Tested:
2015
ManageEngine Asset Explorer v6.1 – XSS Vulnerability
Cross site scripting attack can be performed on the manage engine asset explorer. If the 'publisher' name contains vulnerable script, it gets executed in the browser.
Mitigation:
To mitigate this vulnerability, users are advised to update to the latest version of ManageEngine Asset Explorer.