First published: Thu Jul 11 2019(Updated: )
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via SoftwareListView.do with the parameter swType or swComplianceType.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Assetexplorer | =6.5 | |
Zohocorp Manageengine Assetexplorer | =6.5-6500 | |
Zohocorp Manageengine Assetexplorer | =6.5-6501 | |
Zohocorp Manageengine Assetexplorer | =6.5-6502 | |
Zohocorp Manageengine Assetexplorer | =6.5-6503 | |
Zohocorp Manageengine Assetexplorer | =6.5-6504 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-12596 is medium (6.1).
CVE-2019-12596 affects Zoho ManageEngine AssetExplorer through XSS via the SoftwareListView.do endpoint with the parameters swType or swComplianceType.
Versions 6.5, 6.5-6500, 6.5-6501, 6.5-6502, 6.5-6503, and 6.5-6504 of Zoho ManageEngine AssetExplorer are affected by CVE-2019-12596.
The Common Weakness Enumeration (CWE) ID of CVE-2019-12596 is 79.
Currently, there is no official patch or update available to fix the XSS vulnerability in Zoho ManageEngine AssetExplorer. It is recommended to apply security best practices and implement additional security measures to mitigate the risk.