Lucene search

K
cveMitreCVE-2023-29442
HistoryApr 26, 2023 - 9:15 p.m.

CVE-2023-29442

2023-04-2621:15:08
CWE-79
mitre
web.nvd.nist.gov
22
zoho
manageengine
applications manager
16400
xss
dom
proxy
nvd

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

6.3

Confidence

High

EPSS

0.004

Percentile

72.1%

Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS.

Affected configurations

Nvd
Node
zohocorpmanageengine_applications_managerRange<16.3
OR
zohocorpmanageengine_applications_managerMatch16.3build16300
OR
zohocorpmanageengine_applications_managerMatch16.3build16310
OR
zohocorpmanageengine_applications_managerMatch16.3build16320
OR
zohocorpmanageengine_applications_managerMatch16.3build16330
OR
zohocorpmanageengine_applications_managerMatch16.3build16340
OR
zohocorpmanageengine_applications_managerMatch16.3build16350
OR
zohocorpmanageengine_applications_managerMatch16.3build16360
OR
zohocorpmanageengine_applications_managerMatch16.3build16361
OR
zohocorpmanageengine_applications_managerMatch16.3build16370
OR
zohocorpmanageengine_applications_managerMatch16.3build16380
OR
zohocorpmanageengine_applications_managerMatch16.3build16390
VendorProductVersionCPE
zohocorpmanageengine_applications_manager*cpe:2.3:a:zohocorp:manageengine_applications_manager:*:*:*:*:*:*:*:*
zohocorpmanageengine_applications_manager16.3cpe:2.3:a:zohocorp:manageengine_applications_manager:16.3:build16300:*:*:*:*:*:*
zohocorpmanageengine_applications_manager16.3cpe:2.3:a:zohocorp:manageengine_applications_manager:16.3:build16310:*:*:*:*:*:*
zohocorpmanageengine_applications_manager16.3cpe:2.3:a:zohocorp:manageengine_applications_manager:16.3:build16320:*:*:*:*:*:*
zohocorpmanageengine_applications_manager16.3cpe:2.3:a:zohocorp:manageengine_applications_manager:16.3:build16330:*:*:*:*:*:*
zohocorpmanageengine_applications_manager16.3cpe:2.3:a:zohocorp:manageengine_applications_manager:16.3:build16340:*:*:*:*:*:*
zohocorpmanageengine_applications_manager16.3cpe:2.3:a:zohocorp:manageengine_applications_manager:16.3:build16350:*:*:*:*:*:*
zohocorpmanageengine_applications_manager16.3cpe:2.3:a:zohocorp:manageengine_applications_manager:16.3:build16360:*:*:*:*:*:*
zohocorpmanageengine_applications_manager16.3cpe:2.3:a:zohocorp:manageengine_applications_manager:16.3:build16361:*:*:*:*:*:*
zohocorpmanageengine_applications_manager16.3cpe:2.3:a:zohocorp:manageengine_applications_manager:16.3:build16370:*:*:*:*:*:*
Rows per page:
1-10 of 121

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

6.3

Confidence

High

EPSS

0.004

Percentile

72.1%

Related for CVE-2023-29442