CVE-2019-7426: XSS
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the groupDesc, groupName, groupID, or task parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-7426?
CVE-2019-7426 is an XSS vulnerability that exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2.
What is the severity of CVE-2019-7426?
The severity of CVE-2019-7426 is medium, with a severity value of 6.1.
How does CVE-2019-7426 affect Zoho ManageEngine Netflow Analyzer Professional?
CVE-2019-7426 affects Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone.
Which parameter in the "/netflow/jspui/linkdownalertConfig.jsp" file is vulnerable to XSS?
The groupDesc, groupName, groupID, or task parameter in the "/netflow/jspui/linkdownalertConfig.jsp" file is vulnerable to XSS in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2.
How can I fix CVE-2019-7426?
To fix CVE-2019-7426, it is recommended to update Zoho ManageEngine Netflow Analyzer Professional to a version that addresses the XSS vulnerability.