First published: Tue Jun 30 2015(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Zoho ManageEngine SupportCenter Plus 7.90 allow remote authenticated users to inject arbitrary web script or HTML via the (1) query parameter in the run_query_editor_query module to CustomReportHandler.do, (2) compAcct parameter to jsp/ResetADPwd.jsp, or (3) redirectTo parameter to jsp/CacheScreenWidth.jsp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ManageEngine SupportCenter Plus | =7.90 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5150 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2015-5150, it is recommended to update to the latest version of Zoho ManageEngine SupportCenter Plus that addresses these vulnerabilities.
CVE-2015-5150 affects users of Zoho ManageEngine SupportCenter Plus version 7.90.
CVE-2015-5150 can facilitate cross-site scripting attacks, allowing attackers to inject arbitrary web scripts or HTML.
While there are no specific workarounds for CVE-2015-5150, restricting user input validation can help mitigate risks.