CVE-2018-15169: XSS
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820 allows remote attackers to inject arbitrary web script or HTML via the /deleteMO.do method parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-15169?
CVE-2018-15169 is a reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820.
What is the severity of CVE-2018-15169?
CVE-2018-15169 has a severity value of 6.1, which is considered medium.
How does CVE-2018-15169 affect Zoho ManageEngine Applications Manager?
CVE-2018-15169 allows remote attackers to inject arbitrary web script or HTML via the /deleteMO.do method parameter in Zoho ManageEngine Applications Manager 13 before build 13820.
How can I fix CVE-2018-15169 in Zoho ManageEngine Applications Manager?
To fix CVE-2018-15169, update Zoho ManageEngine Applications Manager to build 13820 or later.
What is the Common Vulnerabilities and Exposures (CVE) identifier for this vulnerability?
The Common Vulnerabilities and Exposures (CVE) identifier for this vulnerability is CVE-2018-15169.