First published: Fri Dec 15 2017(Updated: )
Zoho ManageEngine Password Manager Pro 9 before 9.4 (9400) has reflected XSS in SearchResult.ec and BulkAccessControlView.ec.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Password Manager Pro | >=9.0<9.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-17698 is medium.
CVE-2017-17698 affects Zoho ManageEngine Password Manager Pro version 9 before 9.4 (9400) with reflected XSS vulnerabilities in SearchResult.ec and BulkAccessControlView.ec.
The Common Weakness Enumeration (CWE) ID for CVE-2017-17698 is 79.
To fix CVE-2017-17698 in Zoho ManageEngine Password Manager Pro, update to version 9.4 (9400) or later.
More information about CVE-2017-17698 can be found at the following URL: [https://www.manageengine.com/products/passwordmanagerpro/release-notes.html](https://www.manageengine.com/products/passwordmanagerpro/release-notes.html)