CVE-2018-10075: XSS
Published Jul 2, 2018
·Updated
Cross-site scripting (XSS) vulnerability in Zoho ManageEngine EventLog Analyzer 11.12 allows remote attackers to inject arbitrary web script or HTML via the import logs feature.
Affected Software
1 affected component
ZohoCorp Manageengine Eventlog Analyzer=11.12
Event History
Jul 2, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-10075?
CVE-2018-10075 is a cross-site scripting (XSS) vulnerability in Zoho ManageEngine EventLog Analyzer 11.12.
2
How can remote attackers exploit CVE-2018-10075?
Remote attackers can exploit CVE-2018-10075 by injecting arbitrary web script or HTML via the import logs feature in Zoho ManageEngine EventLog Analyzer 11.12.
3
What is the severity of CVE-2018-10075?
CVE-2018-10075 has a severity rating of medium (6.1).
4
How can I fix CVE-2018-10075?
To fix CVE-2018-10075, update Zoho ManageEngine EventLog Analyzer to version 11.13 or later.
5
Where can I find more information about CVE-2018-10075?
You can find more information about CVE-2018-10075 in the release notes of Zoho ManageEngine EventLog Analyzer 11.13.