vendor:
ManageEngine Desktop Central
by:
Ismail Tasdelen
6.1
CVSS
MEDIUM
Cross-site Scripting
Unknown
CWE
Product Name: ManageEngine Desktop Central
Affected Version From: 10.0.271
Affected Version To: 10.0.271
Patch Exists: Unknown
Related CWE: CVE-2018-16833
CPE: Unknown
Platforms Tested:
2018
ManageEngine Desktop Central 10.0.271 – Cross-Site Scripting
Zoho ManageEngine Desktop Central 10.0.271 has XSS via the "Features & Articles" search field to the /advsearch.do?SUBREQUEST=XMLHTTP URI.
Mitigation:
Unknown