vendor:
Recovery Manager Plus
by:
Ahmet GÜREL
5.4
CVSS
MEDIUM
Persistent Cross-Site Scripting
79
CWE
Product Name: Recovery Manager Plus
Affected Version From: <= 5.3 (Build 5330)
Affected Version To: <= 5.3 (Build 5330)
Patch Exists: YES
Related CWE: CVE-2018-9163
CPE: a:manageengine:recovery_manager_plus:5.3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2018
ManageEngine Recovery Manager Plus 5.3 (Build 5330) – Persistent Cross-Site Scripting
In the Add New Technician (s) section on the /admin/technicians page of the ManageEngine Recovery Manager Plus 5.3 (Build 5330) application, allows remote authenticated users with the Login Name parameter is vulnerable to XSS. The parameters entered are written in the database and affect all users.
Mitigation:
Upgrade to the latest version of ManageEngine Recovery Manager Plus.