CVE-2023-29442: XSS
Published Apr 26, 2023
·Updated
Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS.
Affected Software
12 affected components
ZohoCorp ManageEngine Applications Manager<16.3
ZohoCorp ManageEngine Applications Manager=16.3-build16300
ZohoCorp ManageEngine Applications Manager=16.3-build16310
ZohoCorp ManageEngine Applications Manager=16.3-build16320
ZohoCorp ManageEngine Applications Manager=16.3-build16330
ZohoCorp ManageEngine Applications Manager=16.3-build16340
ZohoCorp ManageEngine Applications Manager=16.3-build16350
ZohoCorp ManageEngine Applications Manager=16.3-build16360
ZohoCorp ManageEngine Applications Manager=16.3-build16361
ZohoCorp ManageEngine Applications Manager=16.3-build16370
ZohoCorp ManageEngine Applications Manager=16.3-build16380
ZohoCorp ManageEngine Applications Manager=16.3-build16390
Event History
Apr 26, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-29442.
2
What is the severity of CVE-2023-29442?
The severity of CVE-2023-29442 is medium with a CVSS score of 6.1.
3
What is the affected software for CVE-2023-29442?
The affected software for CVE-2023-29442 is Zoho ManageEngine Applications Manager before version 16.4.
4
What is the CWE category for CVE-2023-29442?
The CWE category for CVE-2023-29442 is CWE-79 (Cross-site Scripting).
5
Where can I find more information about CVE-2023-29442?
You can find more information about CVE-2023-29442 at the following link: [CVE-2023-29442](https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2023-29442.html)