CVE-2018-16833: XSS
Published Sep 21, 2018
·Updated
Zoho ManageEngine Desktop Central 10.0.271 has XSS via the "Features & Articles" search field to the /advsearch.do?SUBREQUEST=XMLHTTP URI.
Affected Software
1 affected component
ZohoCorp Manageengine Desktop Central=10.0.271
Event History
Sep 21, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2018-16833.
2
What is the severity level of CVE-2018-16833?
The severity level of CVE-2018-16833 is medium with a score of 6.1.
3
How can this vulnerability be exploited?
This vulnerability can be exploited via the "Features & Articles" search field to the /advsearch.do?SUBREQUEST=XMLHTTP URI.
4
What software versions are affected by CVE-2018-16833?
Zoho ManageEngine Desktop Central version 10.0.271 is affected by CVE-2018-16833.
5
Is there a fix available for this vulnerability?
The recommended fix for this vulnerability is to update Zoho ManageEngine Desktop Central to a version that is not affected by this vulnerability.