CVE-2019-7423: XSS
Published Mar 17, 2019
·Updated
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/editProfile.jsp" file in the userName parameter.
Affected Software
1 affected component
ZohoCorp Manageengine Netflow Analyzer=7.0.0.2
Remediation
Patch Available
Event History
Mar 17, 2019
CVE Published
via MITRE·08:02 PM
Data Sourced
via MITRE·08:02 PM
Description
Mar 21, 2019
Data Sourced
via NVD·04:01 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this XSS vulnerability?
The vulnerability ID for this XSS vulnerability is CVE-2019-7423.
2
What is the affected software in this vulnerability?
The affected software in this vulnerability is Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2.
3
What is the severity of CVE-2019-7423?
The severity of CVE-2019-7423 is medium with a CVSS score of 6.1.
4
How can the XSS be exploited in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2?
The XSS vulnerability can be exploited in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 through the userName parameter in the "/netflow/jspui/editProfile.jsp" file.
5
Is there a fix available for this vulnerability?
At the time of writing, there is no specific fix available for CVE-2019-7423. It is recommended to monitor the vendor's website for any updates or patches.