First published: Wed Jun 24 2015(Updated: )
Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 allows remote attackers to inject arbitrary web script or HTML via a Publisher registry entry, which is not properly handled when the machine is scanned.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ManageEngine AssetExplorer | =6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2169 is classified as a moderate severity vulnerability due to its impact on web security through cross-site scripting.
To resolve CVE-2015-2169, update to the latest version of Zoho ManageEngine AssetExplorer that addresses this vulnerability.
CVE-2015-2169 affects users of Zoho ManageEngine AssetExplorer version 6.1 with service pack 6112 installed.
CVE-2015-2169 involves a cross-site scripting (XSS) attack that allows attackers to inject arbitrary web scripts into the application.
CVE-2015-2169 was disclosed in June 2015.