First published: Fri Sep 21 2018(Updated: )
In Zoho ManageEngine SupportCenter Plus before 8.1 Build 8109, there is HTML Injection and Stored XSS via the /ServiceContractDef.do contractName parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Supportcenter Plus | <8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-16965 is medium with a CVSS score of 6.1.
The affected software is Zoho ManageEngine SupportCenter Plus before version 8.1 Build 8109.
HTML Injection is a type of vulnerability that allows an attacker to insert malicious HTML code into a web page, which can lead to various attacks such as phishing or session hijacking.
Stored XSS (Cross-Site Scripting) is a type of vulnerability that occurs when untrusted data is permanently stored on a web application's server and later rendered in a web page, allowing an attacker to inject malicious scripts that can be executed by other users.
To fix CVE-2018-16965 in Zoho ManageEngine SupportCenter Plus, you should upgrade to version 8.1 Build 8109 or later.