CVE-2023-49943: XSS
Published Jan 18, 2024
·Updated
Zoho ManageEngine ServiceDesk Plus MSP before 14504 allows stored XSS (by a low-privileged technician) via a task's name in a time sheet.
Affected Software
5 affected components
ZohoCorp ManageEngine ServiceDesk Plus MSP<14.5
ZohoCorp ManageEngine ServiceDesk Plus MSP=14.5-14500
ZohoCorp ManageEngine ServiceDesk Plus MSP=14.5-14501
ZohoCorp ManageEngine ServiceDesk Plus MSP=14.5-14502
ZohoCorp ManageEngine ServiceDesk Plus MSP=14.5-14503
Event History
Jan 18, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-49943?
CVE-2023-49943 has a moderate severity rating due to its potential for stored XSS exploitation by low-privileged users.
2
How do I fix CVE-2023-49943?
To fix CVE-2023-49943, it is recommended to upgrade to version 14.5-14504 or later of Zoho ManageEngine ServiceDesk Plus MSP.
3
Who is affected by CVE-2023-49943?
CVE-2023-49943 affects all versions of Zoho ManageEngine ServiceDesk Plus MSP prior to 14.5-14504.
4
What type of vulnerability is CVE-2023-49943?
CVE-2023-49943 is a stored cross-site scripting (XSS) vulnerability.
5
Can unauthorized users exploit CVE-2023-49943?
Yes, CVE-2023-49943 can be exploited by low-privileged technicians through task names in a time sheet.