CVE-2018-16965: XSS
In Zoho ManageEngine SupportCenter Plus before 8.1 Build 8109, there is HTML Injection and Stored XSS via the /ServiceContractDef.do contractName parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-16965?
The severity of CVE-2018-16965 is medium with a CVSS score of 6.1.
What is the affected software for CVE-2018-16965?
The affected software is Zoho ManageEngine SupportCenter Plus before version 8.1 Build 8109.
What is HTML Injection?
HTML Injection is a type of vulnerability that allows an attacker to insert malicious HTML code into a web page, which can lead to various attacks such as phishing or session hijacking.
What is Stored XSS?
Stored XSS (Cross-Site Scripting) is a type of vulnerability that occurs when untrusted data is permanently stored on a web application's server and later rendered in a web page, allowing an attacker to inject malicious scripts that can be executed by other users.
How do I fix CVE-2018-16965 in Zoho ManageEngine SupportCenter Plus?
To fix CVE-2018-16965 in Zoho ManageEngine SupportCenter Plus, you should upgrade to version 8.1 Build 8109 or later.