CVE-2024-38870: Stored XSS
Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and OpManager Enterprise Edition versions before 128104, from 128151 before 128238, from 128247 before 128250 are vulnerable to Stored XSS vulnerability in reports module.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38870?
CVE-2024-38870 is classified as a stored Cross-Site Scripting (XSS) vulnerability which could potentially allow attackers to inject malicious scripts.
How do I fix CVE-2024-38870?
To fix CVE-2024-38870, upgrade your Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP, or OpManager Enterprise Edition to the latest patched version beyond 128250.
Which versions are affected by CVE-2024-38870?
CVE-2024-38870 affects ManageEngine products before version 128104 and between versions 128151 to 128238 and 128247 to 128250.
What type of application is vulnerable in CVE-2024-38870?
CVE-2024-38870 is a vulnerability found in the reports module of Zohocorp's network monitoring applications.
Can CVE-2024-38870 lead to data breaches?
Yes, if exploited, CVE-2024-38870 can allow attackers to execute scripts in the context of a user's browser, potentially leading to data breaches.