CVE-2025-27930: Stored XSS
Published Jul 23, 2025
·Updated
Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor.
Affected Software
8 affected components
ZohoCorp ManageEngine Applications Manager<176600
ZohoCorp ManageEngine Applications Manager<17.6
ZohoCorp ManageEngine Applications Manager=17.6
ZohoCorp ManageEngine Applications Manager=17.6-build176100
ZohoCorp ManageEngine Applications Manager=17.6-build176200
ZohoCorp ManageEngine Applications Manager=17.6-build176300
ZohoCorp ManageEngine Applications Manager=17.6-build176500
ZohoCorp ManageEngine Applications Manager=17.6-build176600
Event History
Jul 23, 2025
CVE Published
via MITRE·10:20 AM
Data Sourced
via MITRE·10:20 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-27930?
CVE-2025-27930 is classified as a high-severity vulnerability due to its nature of allowing stored cross-site scripting.
2
How do I fix CVE-2025-27930?
To fix CVE-2025-27930, upgrade to versions of Zohocorp ManageEngine Applications Manager later than 176600.
3
What impact does CVE-2025-27930 have on my system?
CVE-2025-27930 allows attackers to inject malicious scripts into the File/Directory monitor, potentially compromising user sessions and data.
4
Is CVE-2025-27930 being actively exploited?
While there is no reported active exploitation of CVE-2025-27930, it is advisable to address the vulnerability promptly to reduce risk.
5
What versions of ManageEngine Applications Manager are affected by CVE-2025-27930?
CVE-2025-27930 affects Zohocorp ManageEngine Applications Manager versions 176600 and prior.