CVE-2023-38331: XSS
Published Jul 28, 2023
·Updated
Zoho ManageEngine Support Center Plus 14001 and below is vulnerable to stored XSS in the products module.
Affected Software
14 affected components
ZohoCorp Manageengine Supportcenter Plus=8.0-8015
ZohoCorp Manageengine Supportcenter Plus=8.1-8100
ZohoCorp Manageengine Supportcenter Plus=8.1-8101
ZohoCorp Manageengine Supportcenter Plus=8.1-8102
ZohoCorp Manageengine Supportcenter Plus=8.1-8117
ZohoCorp Manageengine Supportcenter Plus=8.1-8118
ZohoCorp Manageengine Supportcenter Plus=8.1-8119
ZohoCorp Manageengine Supportcenter Plus=8.1-8121
ZohoCorp Manageengine Supportcenter Plus=11.0-11000
ZohoCorp Manageengine Supportcenter Plus=11.0-11024
ZohoCorp Manageengine Supportcenter Plus=11.0-11026
ZohoCorp Manageengine Supportcenter Plus=11.0-11027
ZohoCorp Manageengine Supportcenter Plus=14.0-14000
ZohoCorp Manageengine Supportcenter Plus=14.0-14001
Event History
Jul 28, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-38331?
The severity of CVE-2023-38331 is medium with a severity value of 5.4.
2
Which products are affected by CVE-2023-38331?
Zoho ManageEngine Support Center Plus versions 11.0-11000 to 11.0-11027 and versions 14.0-14000 to 14.0-14001 are affected by CVE-2023-38331.
3
What is the vulnerability type of CVE-2023-38331?
CVE-2023-38331 is a stored XSS vulnerability.
4
How can I fix CVE-2023-38331?
There is currently no fix available for CVE-2023-38331. It is recommended to update to a patched version when it becomes available.
5
Where can I find more information about CVE-2023-38331?
You can find more information about CVE-2023-38331 on the Zoho ManageEngine website and the CVE-2023-38331 advisory page.