First published: Thu Mar 15 2018(Updated: )
Zoho ManageEngine EventLog Analyzer version 11.0 build 11000 has Stored XSS related to the index2.do?url=editAlertForm&tab=alert&alert=profile URI and the Edit Alert Profile screen
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Eventlog Analyzer | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-8721.
The severity of CVE-2018-8721 is medium, with a CVSS score of 6.1.
The affected software is Zoho ManageEngine EventLog Analyzer version 11.0 build 11000.
CVE-2018-8721 is a stored cross-site scripting (XSS) vulnerability in Zoho ManageEngine EventLog Analyzer version 11.0 build 11000 related to the index2.do?url=editAlertForm&tab=alert&alert=profile URI and the Edit Alert Profile screen.
Yes, you can find references for CVE-2018-8721 at the following links: http://www.securityfocus.com/bid/103424 and https://pitstop.manageengine.com/portal/community/topic/manageengine-eventlog-analyzer-11-0-build-11000-stored-cross-site-scripting-attack