CVE-2019-12596: XSS
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via SoftwareListView.do with the parameter swType or swComplianceType.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-12596?
The severity of CVE-2019-12596 is medium (6.1).
How does CVE-2019-12596 affect Zoho ManageEngine AssetExplorer?
CVE-2019-12596 affects Zoho ManageEngine AssetExplorer through XSS via the SoftwareListView.do endpoint with the parameters swType or swComplianceType.
Which versions of Zoho ManageEngine AssetExplorer are affected by CVE-2019-12596?
Versions 6.5, 6.5-6500, 6.5-6501, 6.5-6502, 6.5-6503, and 6.5-6504 of Zoho ManageEngine AssetExplorer are affected by CVE-2019-12596.
What is the Common Weakness Enumeration (CWE) ID of CVE-2019-12596?
The Common Weakness Enumeration (CWE) ID of CVE-2019-12596 is 79.
How can I fix the XSS vulnerability in Zoho ManageEngine AssetExplorer?
Currently, there is no official patch or update available to fix the XSS vulnerability in Zoho ManageEngine AssetExplorer. It is recommended to apply security best practices and implement additional security measures to mitigate the risk.