Vulnerabilities > Zohocorp > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-04-04 CVE-2019-10273 Improper Authentication vulnerability in Zohocorp Manageengine Servicedesk Plus 9.3
Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users.
network
low complexity
zohocorp CWE-287
4.3
2019-03-25 CVE-2017-9376 Improper Input Validation vulnerability in Zohocorp Manageengine Servicedesk Plus
ManageEngine ServiceDesk Plus before 9314 contains a local file inclusion vulnerability in the defModule parameter in DefaultConfigDef.do and AssetDefaultConfigDef.do.
network
low complexity
zohocorp CWE-20
6.5
2019-03-21 CVE-2019-7425 Cross-site Scripting vulnerability in Zohocorp Manageengine Netflow Analyzer 7.0.0.2
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the task parameter.
network
low complexity
zohocorp CWE-79
6.1
2019-03-21 CVE-2019-7424 Cross-site Scripting vulnerability in Zohocorp Manageengine Netflow Analyzer 7.0.0.2
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/index.jsp" file in the view GET parameter or any of these POST parameters: autorefTime, section, snapshot, viewOpt, viewAll, view, or groupSelName.
network
low complexity
zohocorp CWE-79
6.1
2019-03-21 CVE-2019-7423 Cross-site Scripting vulnerability in Zohocorp Manageengine Netflow Analyzer 7.0.0.2
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/editProfile.jsp" file in the userName parameter.
network
low complexity
zohocorp CWE-79
6.1
2019-03-21 CVE-2019-7422 Cross-site Scripting vulnerability in Zohocorp Manageengine Netflow Analyzer 7.0.0.2
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/addMailSettings.jsp" file in the gF parameter.
network
low complexity
zohocorp CWE-79
6.1
2019-02-17 CVE-2019-8394 Unrestricted Upload of File with Dangerous Type vulnerability in Zohocorp Manageengine Servicedesk Plus
Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.
network
low complexity
zohocorp CWE-434
6.5
2018-12-26 CVE-2018-20485 Cross-site Scripting vulnerability in Zohocorp Manageengine Adselfservice Plus
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature.
network
low complexity
zohocorp CWE-79
6.1
2018-12-26 CVE-2018-20484 Cross-site Scripting vulnerability in Zohocorp Manageengine Adselfservice Plus 5.7
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation.
network
low complexity
zohocorp CWE-79
6.1
2018-12-21 CVE-2018-20339 Cross-site Scripting vulnerability in Zohocorp Manageengine Opmanager 12.3
Zoho ManageEngine OpManager 12.3 before build 123239 allows XSS in the Notes column of the Alarms section.
network
low complexity
zohocorp CWE-79
6.1