CVE-2018-5799: XSS
Published Mar 30, 2018
·Updated
In Zoho ManageEngine ServiceDesk Plus before 9403, an XSS issue allows an attacker to run arbitrary JavaScript via a /api/request/?OPERATIONNAME= URI, aka SD-69139.
Affected Software
1 affected component
ZohoCorp ManageEngine ServiceDesk Plus<9403
Event History
Mar 30, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Data Sourced
via NVD·01:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2018-5799.
2
What is the severity of CVE-2018-5799?
The severity of CVE-2018-5799 is medium (6.1).
3
How does CVE-2018-5799 affect Zoho ManageEngine ServiceDesk Plus?
CVE-2018-5799 affects Zoho ManageEngine ServiceDesk Plus versions before 9403.
4
What is the CWE ID of CVE-2018-5799?
The CWE ID of CVE-2018-5799 is CWE-79.
5
How can I fix the XSS issue associated with CVE-2018-5799?
To fix the XSS issue associated with CVE-2018-5799, update Zoho ManageEngine ServiceDesk Plus to version 9403 or later.