CVE-2024-36038: Stored XSS
Zoho ManageEngine ITOM products versions from 128234 to 128248 are affected by the stored cross-site scripting vulnerability in the proxy server option.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36038?
CVE-2024-36038 is classified as a medium severity vulnerability due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2024-36038?
To mitigate CVE-2024-36038, you should upgrade your Zoho ManageEngine ITOM product to a version that is not affected, specifically above version 128248.
What types of attacks can CVE-2024-36038 facilitate?
CVE-2024-36038 can facilitate stored cross-site scripting attacks, allowing an attacker to inject malicious scripts into the application.
Which versions of Zoho ManageEngine ITOM are affected by CVE-2024-36038?
CVE-2024-36038 affects Zoho ManageEngine ITOM versions from 128234 to 128248.
Who is affected by CVE-2024-36038?
Organizations using affected versions of Zoho ManageEngine ITOM products, specifically those operating between versions 128234 and 128248, are vulnerable to CVE-2024-36038.