First published: Tue Mar 13 2018(Updated: )
Cross-site scripting (XSS) in Zoho ManageEngine EventLog Analyzer before 11.12 Build 11120 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Eventlog Analyzer | <11.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-7405 is medium with a CVSS score of 6.1.
CVE-2018-7405 allows remote attackers to inject arbitrary web script or HTML in Zoho ManageEngine EventLog Analyzer.
Zoho ManageEngine EventLog Analyzer before 11.12 Build 11120 is affected by CVE-2018-7405.
Remote attackers can exploit CVE-2018-7405 by injecting arbitrary web script or HTML through unspecified vectors.
Yes, upgrading to Zoho ManageEngine EventLog Analyzer version 11.12 Build 11120 or later fixes CVE-2018-7405.