CVE-2019-7427: XSS
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the autorefTime or graphTypes parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-7427?
CVE-2019-7427 is a vulnerability that allows cross-site scripting (XSS) attacks in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2.
How does the XSS vulnerability in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 work?
The XSS occurs in the Administration zone at the "/netflow/jspui/linkdownalertConfig.jsp" file, specifically in the autorefTime or graphTypes parameter.
What is the severity of CVE-2019-7427?
The severity of CVE-2019-7427 is medium, with a CVSS score of 6.1.
How can I fix the XSS vulnerability in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2?
To fix the vulnerability, it is recommended to update to a version that addresses the XSS issue.
Where can I find more information about CVE-2019-7427?
You can find more information about CVE-2019-7427 on the following websites: [1] http://packetstormsecurity.com/files/151585/Zoho-ManageEngine-Netflow-Analyzer-Professional-7.0.0.2-XSS.html [2] http://seclists.org/fulldisclosure/2019/Feb/29