Un cross-site scripting (XSS) in Zoho ManageEngine NetFlow Analyzer riflette prima di build 123137, Network Configuration Manager prima di build 123128, OpManager prima di costruire 123.148, OpUtils prima costruzione 123161, e Firewall Analyzer prima di costruire 123.147 consente agli aggressori remoti di inserire lo script Web arbitrario o HTML tramite il parametro ‘operazione’ a /servlet/com.adventnet.me.opmanager.servlet.FailOverHelperServlet. |
http://seclists.org/fulldisclosure/2018/Jul/75 http://packetstormsecurity.com/files/148635/Zoho-ManageEngine-13-13790-build-XSS-File-Read-File-Deletion.html http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201807-036 https://github.com/unh3x/just4cve/issues/10 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12998 |
Vulnerabilità: CVE-2018-12998
