First published: Tue Sep 20 2011(Updated: )
Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus (SDP) before 8012 allows remote attackers to inject arbitrary web script or HTML via the searchText parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zoho ManageEngine ServiceDesk Plus | <=8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1510 is classified as a medium severity vulnerability due to its potential for exploitation through cross-site scripting.
To mitigate CVE-2011-1510, upgrade ManageEngine ServiceDesk Plus to version 8012 or later.
CVE-2011-1510 affects all versions of ManageEngine ServiceDesk Plus prior to 8012.
CVE-2011-1510 enables remote attackers to perform cross-site scripting (XSS) attacks.
The searchText parameter in SolutionSearch.do is exploited in CVE-2011-1510.