Lucene search

K
nvd[email protected]NVD:CVE-2023-38331
HistoryJul 28, 2023 - 2:15 a.m.

CVE-2023-38331

2023-07-2802:15:10
CWE-79
web.nvd.nist.gov
2
zoho manageengine
support center plus
stored xss
vulnerability

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.008

Percentile

81.6%

Zoho ManageEngine Support Center Plus 14001 and below is vulnerable to stored XSS in the products module.

Affected configurations

Nvd
Node
zohocorpmanageengine_supportcenter_plusMatch8.08015
OR
zohocorpmanageengine_supportcenter_plusMatch8.18100
OR
zohocorpmanageengine_supportcenter_plusMatch8.18101
OR
zohocorpmanageengine_supportcenter_plusMatch8.18102
OR
zohocorpmanageengine_supportcenter_plusMatch8.18117
OR
zohocorpmanageengine_supportcenter_plusMatch8.18118
OR
zohocorpmanageengine_supportcenter_plusMatch8.18119
OR
zohocorpmanageengine_supportcenter_plusMatch8.18121
OR
zohocorpmanageengine_supportcenter_plusMatch11.011000
OR
zohocorpmanageengine_supportcenter_plusMatch11.011024
OR
zohocorpmanageengine_supportcenter_plusMatch11.011026
OR
zohocorpmanageengine_supportcenter_plusMatch11.011027
OR
zohocorpmanageengine_supportcenter_plusMatch14.014000
OR
zohocorpmanageengine_supportcenter_plusMatch14.014001
VendorProductVersionCPE
zohocorpmanageengine_supportcenter_plus8.0cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:8.0:8015:*:*:*:*:*:*
zohocorpmanageengine_supportcenter_plus8.1cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:8.1:8100:*:*:*:*:*:*
zohocorpmanageengine_supportcenter_plus8.1cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:8.1:8101:*:*:*:*:*:*
zohocorpmanageengine_supportcenter_plus8.1cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:8.1:8102:*:*:*:*:*:*
zohocorpmanageengine_supportcenter_plus8.1cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:8.1:8117:*:*:*:*:*:*
zohocorpmanageengine_supportcenter_plus8.1cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:8.1:8118:*:*:*:*:*:*
zohocorpmanageengine_supportcenter_plus8.1cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:8.1:8119:*:*:*:*:*:*
zohocorpmanageengine_supportcenter_plus8.1cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:8.1:8121:*:*:*:*:*:*
zohocorpmanageengine_supportcenter_plus11.0cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:11.0:11000:*:*:*:*:*:*
zohocorpmanageengine_supportcenter_plus11.0cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:11.0:11024:*:*:*:*:*:*
Rows per page:
1-10 of 141

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.008

Percentile

81.6%

Related for NVD:CVE-2023-38331