CVE-2025-9787: Stored XSS
Published Dec 18, 2025
·Updated
Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view.
Affected Software
17 affected components
Zohocorp ManageEngine Applications Manager<=177400
Zohocorp ManageEngine Applications Manager>=17.4<17.7
Zohocorp ManageEngine Applications Manager=17.3-build173300
Zohocorp ManageEngine Applications Manager=17.3-build173301
Zohocorp ManageEngine Applications Manager=17.3-build173302
Zohocorp ManageEngine Applications Manager=17.3-build173303
Zohocorp ManageEngine Applications Manager=17.3-build173304
Zohocorp ManageEngine Applications Manager=17.7
Zohocorp ManageEngine Applications Manager=17.7-build177000
Zohocorp ManageEngine Applications Manager=17.7-build177100
Zohocorp ManageEngine Applications Manager=17.7-build177200
Zohocorp ManageEngine Applications Manager=17.7-build177201
Zohocorp ManageEngine Applications Manager=17.7-build177202
Zohocorp ManageEngine Applications Manager=17.7-build177203
Zohocorp ManageEngine Applications Manager=17.7-build177204
Zohocorp ManageEngine Applications Manager=17.7-build177300
Zohocorp ManageEngine Applications Manager=17.7-build177400
Remediation
Event History
Dec 18, 2025
CVE Published
via MITRE·02:14 PM
Data Sourced
via MITRE·02:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-9787?
CVE-2025-9787 is classified as a medium severity Stored Cross-Site Scripting vulnerability.
2
How do I fix CVE-2025-9787?
To fix CVE-2025-9787, upgrade Zohocorp ManageEngine Applications Manager to version 177401 or later.
3
Which versions of ManageEngine Applications Manager are affected by CVE-2025-9787?
CVE-2025-9787 affects ManageEngine Applications Manager versions 177400 and below.
4
What is a Stored Cross-Site Scripting vulnerability in CVE-2025-9787?
A Stored Cross-Site Scripting vulnerability in CVE-2025-9787 allows attackers to inject malicious scripts that can be executed in the context of users accessing the NOC view.
5
How can CVE-2025-9787 impact my organization?
CVE-2025-9787 can lead to unauthorized access to sensitive user data, session hijacking, or redirecting users to malicious sites.