CVE-2017-11687: XSS
Multiple Persistent cross-site scripting (XSS) vulnerabilities in Event log parsing and Display functions in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or HTML via syslog.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11687?
CVE-2017-11687 is classified as a medium severity vulnerability due to its potential impact on web security.
What are the potential impacts of CVE-2017-11687?
CVE-2017-11687 could allow remote attackers to execute arbitrary web scripts or HTML, leading to persistent cross-site scripting vulnerabilities.
How do I fix CVE-2017-11687?
To fix CVE-2017-11687, upgrade your Zoho ManageEngine Event Log Analyzer to the latest version that addresses this vulnerability.
Which versions of ManageEngine are affected by CVE-2017-11687?
CVE-2017-11687 affects Zoho ManageEngine Event Log Analyzer versions 11.4 and 11.5.
Is CVE-2017-11687 a persistent or non-persistent XSS vulnerability?
CVE-2017-11687 is classified as a persistent cross-site scripting (XSS) vulnerability.