CVE-2018-15608: XSS
Published Aug 28, 2018
·Updated
Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.
Affected Software
1 affected component
ManageEngine ADManager Plus=6.5.7
Event History
Aug 28, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-15608?
CVE-2018-15608 is a vulnerability in Zoho ManageEngine ADManager Plus 6.5.7 that allows HTML injection on the "AD Delegation" "Help Desk Technicians" screen.
2
Is Zoho ManageEngine ADManager Plus 6.5.7 affected by CVE-2018-15608?
Yes, Zoho ManageEngine ADManager Plus 6.5.7 is affected by CVE-2018-15608.
3
What is the severity of CVE-2018-15608?
The severity of CVE-2018-15608 is medium with a CVSS score of 6.1.
4
How can I fix CVE-2018-15608?
To fix CVE-2018-15608, it is recommended to update Zoho ManageEngine ADManager Plus to a version that has the vulnerability patched.
5
Where can I find more information about CVE-2018-15608?
You can find more information about CVE-2018-15608 at the following link: [CVE-2018-15608](https://www.exploit-db.com/exploits/45254/).