First published: Wed Jan 06 2021(Updated: )
Zoho ManageEngine Desktop Central 10.0.430 allows HTML injection via a modified Report Name in a New Custom Report.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Desktop Central | =10.0.430 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-16962 is medium with a CVSS score of 5.4.
CVE-2019-16962 allows HTML injection via a modified Report Name in a New Custom Report in Zoho ManageEngine Desktop Central 10.0.430.
To fix CVE-2019-16962, you should update Zoho ManageEngine Desktop Central to version 10.0.431 or higher.
The CWE ID related to CVE-2019-16962 is CWE-79 (Cross-site Scripting).