First published: Wed Jul 17 2024(Updated: )
Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and OpManager Enterprise Edition versions before 128104, from 128151 before 128238, from 128247 before 128250 are vulnerable to Stored XSS vulnerability in reports module.
Credit: 0fc0942c-577d-436f-ae8e-945763c79b02
Affected Software | Affected Version | How to fix |
---|---|---|
ManageEngine OpManager MSP | <128104>=128151<128238>=128247<128250 | |
ManageEngine OpManager Plus | <128104>=128151<128238>=128247<128250 | |
ManageEngine OpManager MSP | <128104>=128151<128238>=128247<128250 | |
Zoho Corp ManageEngine OpManager Enterprise Edition | <128104>=128151<128238>=128247<128250 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-38870 is classified as a stored Cross-Site Scripting (XSS) vulnerability which could potentially allow attackers to inject malicious scripts.
To fix CVE-2024-38870, upgrade your Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP, or OpManager Enterprise Edition to the latest patched version beyond 128250.
CVE-2024-38870 affects ManageEngine products before version 128104 and between versions 128151 to 128238 and 128247 to 128250.
CVE-2024-38870 is a vulnerability found in the reports module of Zohocorp's network monitoring applications.
Yes, if exploited, CVE-2024-38870 can allow attackers to execute scripts in the context of a user's browser, potentially leading to data breaches.