CVE-2023-38333: XSS
Published Aug 10, 2023
·Updated
Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in.
Affected Software
7 affected components
ZohoCorp ManageEngine Applications Manager<16.5
ZohoCorp ManageEngine Applications Manager=16.5
ZohoCorp ManageEngine Applications Manager=16.5-build16500
ZohoCorp ManageEngine Applications Manager=16.5-build16510
ZohoCorp ManageEngine Applications Manager=16.5-build16511
ZohoCorp ManageEngine Applications Manager=16.5-build16520
ZohoCorp ManageEngine Applications Manager=16.5-build16530
Event History
Aug 10, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-38333?
CVE-2023-38333 is a vulnerability in Zoho ManageEngine Applications Manager that allows for reflected XSS attacks while logged in.
2
What is the severity of CVE-2023-38333?
The severity of CVE-2023-38333 is medium, with a CVSS score of 6.1.
3
How does CVE-2023-38333 affect Zoho ManageEngine Applications Manager?
CVE-2023-38333 affects Zoho ManageEngine Applications Manager versions prior to 16.5-build16530.
4
How can I fix CVE-2023-38333 in Zoho ManageEngine Applications Manager?
To fix CVE-2023-38333 in Zoho ManageEngine Applications Manager, upgrade to version 16.5-build16530 or later.
5
Are there any security updates available for CVE-2023-38333?
Yes, security updates for CVE-2023-38333 are available. Please refer to the following link for more information: [link]https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2023-38333.html[endlink]