CVE-2018-12996: XSS
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager before 13 (Build 13800) allows remote attackers to inject arbitrary web script or HTML via the parameter 'method' to GraphicalView.do.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-12996?
CVE-2018-12996 is a reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager before 13 (Build 13800) that allows remote attackers to inject arbitrary web script or HTML via the 'method' parameter to GraphicalView.do.
How severe is CVE-2018-12996?
CVE-2018-12996 has a severity level of 6.1 (medium).
What software is affected by CVE-2018-12996?
Zohocorp Manageengine Applications Manager version 13 (Build 13800) and earlier versions are affected by CVE-2018-12996.
How can an attacker exploit CVE-2018-12996?
An attacker can exploit CVE-2018-12996 by sending a crafted request with malicious web script or HTML through the 'method' parameter to GraphicalView.do, which will be executed on the victim's browser.
Are there any references for CVE-2018-12996?
Here are some references related to CVE-2018-12996: - [Packet Storm Security](http://packetstormsecurity.com/files/148635/Zoho-ManageEngine-13-13790-build-XSS-File-Read-File-Deletion.html) - [SecLists Fulldisclosure](http://seclists.org/fulldisclosure/2018/Jul/71) - [CVE Details - CNNVD](http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201807-038)