CVE-2016-4888: XSS
Published Apr 14, 2017
·Updated
Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine ServiceDesk Plus before 9.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
1 affected component
ZohoCorp Servicedesk Plus<=9.1
Event History
Apr 14, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4888?
CVE-2016-4888 has been categorized as a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2016-4888?
To fix CVE-2016-4888, upgrade ZOHO ManageEngine ServiceDesk Plus to version 9.2 or later.
3
What types of attacks can exploit CVE-2016-4888?
CVE-2016-4888 can be exploited through cross-site scripting attacks, allowing attackers to inject malicious web scripts or HTML.
4
Who is affected by CVE-2016-4888?
Users of ZOHO ManageEngine ServiceDesk Plus versions prior to 9.2 are affected by CVE-2016-4888.
5
What is the impact of CVE-2016-4888?
The impact of CVE-2016-4888 can result in unauthorized actions being performed on behalf of affected users through the execution of injected scripts.