Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-94825
HistoryDec 02, 2021 - 12:00 a.m.

ZOHO ManageEngine SupportCenter Plus Cross-Site Scripting Vulnerability (CNVD-2021-94825)

2021-12-0200:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
zoho manageengine
supportcenter plus
cross-site scripting
vulnerability
authentication credentials
attackers
web-based software

EPSS

0.002

Percentile

51.8%

ZOHO ManageEngine SupportCenter Plus is a web-based customer support software from ZOHO, Inc. A cross-site scripting vulnerability exists in ZOHO ManageEngine SupportCenter Plus, which stems from the product’s failure to validate user identities and could be exploited by attackers to obtain a victim’s cookie-based authentication credentials of the victim.

EPSS

0.002

Percentile

51.8%

Related for CNVD-2021-94825