CVE-2019-16268: XSS
Zoho ManageEngine Remote Access Plus 10.0.259 allows HTML injection via the Description field on the Admin - User Administration userMgmt.do?actionToCall=ShowUser screen.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-16268?
CVE-2019-16268 is a vulnerability that allows HTML injection via the Description field on the Admin - User Administration screen in Zoho ManageEngine Remote Access Plus 10.0.259.
How severe is CVE-2019-16268?
CVE-2019-16268 has a severity rating of 4.8 (medium).
How does HTML injection work in CVE-2019-16268?
HTML injection occurs when an attacker is able to inject and execute arbitrary HTML code in the Description field on the Admin - User Administration screen.
What is the affected software version for CVE-2019-16268?
Zoho ManageEngine Remote Access Plus version 10.0.259 is affected by CVE-2019-16268.
How can I mitigate CVE-2019-16268?
To mitigate CVE-2019-16268, it is recommended to update Zoho ManageEngine Remote Access Plus to a version that includes the fix for this vulnerability.