CVE-2023-23078: XSS
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via the comment field when changing the credentials in the Assets.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-23078?
CVE-2023-23078 is a Cross Site Scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14.
How does CVE-2023-23078 occur?
CVE-2023-23078 occurs when the comment field is used to change credentials in the Assets of Zoho ManageEngine ServiceDesk Plus 14.
What is the severity of CVE-2023-23078?
CVE-2023-23078 has a severity level of medium.
How can I fix CVE-2023-23078?
To fix CVE-2023-23078, users should update to a patched version of Zoho ManageEngine ServiceDesk Plus 14.
Where can I find more information about CVE-2023-23078?
More information about CVE-2023-23078 can be found at the following references: [Reference 1](https://bugbounty.zohocorp.com/bb/#/bug/101000006458675?tab=originator) and [Reference 2](https://www.manageengine.com/products/service-desk/CVE-2023-23078.html).