Lucene search

K
nvd[email protected]NVD:CVE-2023-29442
HistoryApr 26, 2023 - 9:15 p.m.

CVE-2023-29442

2023-04-2621:15:08
CWE-79
web.nvd.nist.gov
1
zoho manageengine
applications manager
xss
proxy.html

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.004

Percentile

72.1%

Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS.

Affected configurations

Nvd
Node
zohocorpmanageengine_applications_managerRange<16.3
OR
zohocorpmanageengine_applications_managerMatch16.3build16300
OR
zohocorpmanageengine_applications_managerMatch16.3build16310
OR
zohocorpmanageengine_applications_managerMatch16.3build16320
OR
zohocorpmanageengine_applications_managerMatch16.3build16330
OR
zohocorpmanageengine_applications_managerMatch16.3build16340
OR
zohocorpmanageengine_applications_managerMatch16.3build16350
OR
zohocorpmanageengine_applications_managerMatch16.3build16360
OR
zohocorpmanageengine_applications_managerMatch16.3build16361
OR
zohocorpmanageengine_applications_managerMatch16.3build16370
OR
zohocorpmanageengine_applications_managerMatch16.3build16380
OR
zohocorpmanageengine_applications_managerMatch16.3build16390
VendorProductVersionCPE
zohocorpmanageengine_applications_manager*cpe:2.3:a:zohocorp:manageengine_applications_manager:*:*:*:*:*:*:*:*
zohocorpmanageengine_applications_manager16.3cpe:2.3:a:zohocorp:manageengine_applications_manager:16.3:build16300:*:*:*:*:*:*
zohocorpmanageengine_applications_manager16.3cpe:2.3:a:zohocorp:manageengine_applications_manager:16.3:build16310:*:*:*:*:*:*
zohocorpmanageengine_applications_manager16.3cpe:2.3:a:zohocorp:manageengine_applications_manager:16.3:build16320:*:*:*:*:*:*
zohocorpmanageengine_applications_manager16.3cpe:2.3:a:zohocorp:manageengine_applications_manager:16.3:build16330:*:*:*:*:*:*
zohocorpmanageengine_applications_manager16.3cpe:2.3:a:zohocorp:manageengine_applications_manager:16.3:build16340:*:*:*:*:*:*
zohocorpmanageengine_applications_manager16.3cpe:2.3:a:zohocorp:manageengine_applications_manager:16.3:build16350:*:*:*:*:*:*
zohocorpmanageengine_applications_manager16.3cpe:2.3:a:zohocorp:manageengine_applications_manager:16.3:build16360:*:*:*:*:*:*
zohocorpmanageengine_applications_manager16.3cpe:2.3:a:zohocorp:manageengine_applications_manager:16.3:build16361:*:*:*:*:*:*
zohocorpmanageengine_applications_manager16.3cpe:2.3:a:zohocorp:manageengine_applications_manager:16.3:build16370:*:*:*:*:*:*
Rows per page:
1-10 of 121

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.004

Percentile

72.1%

Related for NVD:CVE-2023-29442