CVE-2018-9163: XSS
Published Apr 2, 2018
·Updated
A stored Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Recovery Manager Plus before 5.3 (Build 5350) allows remote authenticated users (with Add New Technician permissions) to inject arbitrary web script or HTML via the loginName field to technicianAction.do.
Affected Software
1 affected component
ZohoCorp Manageengine Recovery Manager Plus<5.3
Event History
Apr 2, 2018
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
Description
Data Sourced
via NVD·12:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-9163?
CVE-2018-9163 is considered a medium severity vulnerability due to its stored XSS nature.
2
How do I fix CVE-2018-9163?
To fix CVE-2018-9163, upgrade Zoho ManageEngine Recovery Manager Plus to version 5.3 (Build 5350) or later.
3
Who is affected by CVE-2018-9163?
CVE-2018-9163 affects remote authenticated users with 'Add New Technician' permissions.
4
What type of vulnerability is CVE-2018-9163?
CVE-2018-9163 is a stored Cross-site scripting (XSS) vulnerability.
5
Where can CVE-2018-9163 be exploited?
CVE-2018-9163 can be exploited via the loginName field in the technicianAction.do interface.