CVE-2017-17698: XSS
Published Dec 15, 2017
·Updated
Zoho ManageEngine Password Manager Pro 9 before 9.4 (9400) has reflected XSS in SearchResult.ec and BulkAccessControlView.ec.
Affected Software
1 affected component
ZohoCorp ManageEngine Password Manager Pro>=9.0<9.4
Event History
Dec 15, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-17698?
The severity of CVE-2017-17698 is medium.
2
How does CVE-2017-17698 affect Zoho ManageEngine Password Manager Pro?
CVE-2017-17698 affects Zoho ManageEngine Password Manager Pro version 9 before 9.4 (9400) with reflected XSS vulnerabilities in SearchResult.ec and BulkAccessControlView.ec.
3
What is the Common Weakness Enumeration (CWE) ID for CVE-2017-17698?
The Common Weakness Enumeration (CWE) ID for CVE-2017-17698 is 79.
4
How do I fix CVE-2017-17698 in Zoho ManageEngine Password Manager Pro?
To fix CVE-2017-17698 in Zoho ManageEngine Password Manager Pro, update to version 9.4 (9400) or later.
5
Where can I find more information about CVE-2017-17698?
More information about CVE-2017-17698 can be found at the following URL: [https://www.manageengine.com/products/passwordmanagerpro/release-notes.html](https://www.manageengine.com/products/passwordmanagerpro/release-notes.html)