First published: Tue May 07 2019(Updated: )
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the autorefTime or graphTypes parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Netflow Analyzer | =7.0.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7427 is a vulnerability that allows cross-site scripting (XSS) attacks in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2.
The XSS occurs in the Administration zone at the "/netflow/jspui/linkdownalertConfig.jsp" file, specifically in the autorefTime or graphTypes parameter.
The severity of CVE-2019-7427 is medium, with a CVSS score of 6.1.
To fix the vulnerability, it is recommended to update to a version that addresses the XSS issue.
You can find more information about CVE-2019-7427 on the following websites: [1] http://packetstormsecurity.com/files/151585/Zoho-ManageEngine-Netflow-Analyzer-Professional-7.0.0.2-XSS.html [2] http://seclists.org/fulldisclosure/2019/Feb/29