CVE-2019-8926: XSS
Published May 17, 2019
·Updated
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/popup1.jsp file via these GET parameters: bussAlert, customDev, and selSource.
Affected Software
1 affected component
ZohoCorp Manageengine Netflow Analyzer=7.0.0.2
Event History
May 17, 2019
CVE Published
via MITRE·01:57 PM
Data Sourced
via MITRE·01:57 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-8926.
2
What is the severity of CVE-2019-8926?
The severity of CVE-2019-8926 is medium, with a CVSS score of 6.1.
3
What software is affected by CVE-2019-8926?
Zoho ManageEngine Netflow Analyzer Professional version 7.0.0.2 is affected by CVE-2019-8926.
4
How does the vulnerability manifest in Zoho ManageEngine Netflow Analyzer Professional?
The vulnerability manifests as a cross-site scripting (XSS) issue in the Administration zone /netflow/jspui/popup1.jsp file via the GET parameters bussAlert, customDev, and selSource.
5
Are there any known exploits for CVE-2019-8926?
Yes, there are known exploits for CVE-2019-8926. Please refer to the provided references for more information.