CVE-2017-11685: XSS
Multiple Reflective cross-site scripting (XSS) vulnerabilities in search and display of event data in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or HTML, as demonstrated by the fName parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11685?
CVE-2017-11685 is classified as a high severity vulnerability due to the potential for remote code execution via cross-site scripting.
How do I fix CVE-2017-11685?
To remediate CVE-2017-11685, upgrade Zoho ManageEngine Event Log Analyzer to the latest version that addresses these vulnerabilities.
What type of attacks can be launched using CVE-2017-11685?
Attackers can exploit CVE-2017-11685 to launch reflective cross-site scripting attacks, potentially compromising user sessions.
Which versions of Zoho ManageEngine Event Log Analyzer are affected by CVE-2017-11685?
CVE-2017-11685 affects Zoho ManageEngine Event Log Analyzer versions 11.4 and 11.5.
Is it possible to prevent exploitation of CVE-2017-11685?
Preventing exploitation of CVE-2017-11685 includes input validation and escaping output to mitigate cross-site scripting risks.