First published: Fri Jul 07 2023(Updated: )
Zoho ManageEngine ADAudit Plus before 7100 allows XSS via the username field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp ManageEngine ADAudit Plus | <7.0 | |
Zohocorp ManageEngine ADAudit Plus | =7.0 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7000 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7002 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7003 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7004 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7005 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7006 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7007 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7008 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7050 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7051 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7052 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7053 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7054 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7055 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7060 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7062 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7063 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7065 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7080 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7081 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7082 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7090 | |
Zohocorp ManageEngine ADAudit Plus | =7.0-7091 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-37308 is a vulnerability in Zoho ManageEngine ADAudit Plus that allows cross-site scripting (XSS) attacks via the username field.
CVE-2023-37308 has a severity rating of 5.4, which is considered medium.
CVE-2023-37308 affects Zoho ManageEngine ADAudit Plus versions before 7100 and allows XSS attacks through the username field.
The Common Vulnerabilities and Exposures (CVE) identifier for this vulnerability is CVE-2023-37308.
Yes, the fix for CVE-2023-37308 is to update Zoho ManageEngine ADAudit Plus to version 7100 or later.