First published: Tue Apr 05 2022(Updated: )
Zoho ManageEngine SupportCenter Plus before 11020 allows Stored XSS in the request history.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Supportcenter Plus | <11.0 | |
Zohocorp Manageengine Supportcenter Plus | =11.0 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11000 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11001 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11002 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11003 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11004 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11005 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11006 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11007 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11008 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11009 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11010 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11011 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11012 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11013 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11014 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11015 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11016 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11017 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11018 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25373 is a vulnerability in Zoho ManageEngine SupportCenter Plus that allows for stored cross-site scripting (XSS) attacks in the request history.
CVE-2022-25373 has a severity rating of 5.4, which is considered medium.
Zoho ManageEngine SupportCenter Plus versions up to 11.0 build 11019 are affected by CVE-2022-25373.
To fix CVE-2022-25373, it is recommended to upgrade Zoho ManageEngine SupportCenter Plus to version 11.0 build 11020 or later.
Yes, you can find references for CVE-2022-25373 at the following links: [1] [2] [3]