Vulnerabilities > Zohocorp > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-08-10 CVE-2023-38333 Cross-site Scripting vulnerability in Zohocorp Manageengine Applications Manager
Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in.
network
low complexity
zohocorp CWE-79
6.1
2023-08-04 CVE-2023-38332 Unspecified vulnerability in Zohocorp Manageengine Admanager Plus
Zoho ManageEngine ADManager Plus through 7201 allow authenticated users to take over another user's account via sensitive information disclosure.
network
low complexity
zohocorp
6.5
2023-07-28 CVE-2023-38331 Cross-site Scripting vulnerability in Zohocorp Manageengine Supportcenter Plus
Zoho ManageEngine Support Center Plus 14001 and below is vulnerable to stored XSS in the products module.
network
low complexity
zohocorp CWE-79
5.4
2023-07-07 CVE-2023-34197 Unspecified vulnerability in Zohocorp Manageengine Servicedesk Plus 8.1/8.2/9.0
Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation vulnerability in the Release module that allows unprivileged users to access the Reminders of a release ticket and make modifications.
network
low complexity
zohocorp
5.4
2023-07-07 CVE-2023-37308 Cross-site Scripting vulnerability in Zohocorp Manageengine Adaudit Plus
Zoho ManageEngine ADAudit Plus before 7100 allows XSS via the username field.
network
low complexity
zohocorp CWE-79
5.4
2023-07-05 CVE-2023-35786 XXE vulnerability in Zohocorp Manageengine Admanager Plus
Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files.
network
low complexity
zohocorp CWE-611
4.9
2023-04-26 CVE-2023-29442 Cross-site Scripting vulnerability in Zohocorp Manageengine Applications Manager
Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS.
network
low complexity
zohocorp CWE-79
6.1
2023-04-26 CVE-2023-29443 XXE vulnerability in Zohocorp products
Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint.
network
low complexity
zohocorp CWE-611
4.9
2023-03-30 CVE-2022-43473 XXE vulnerability in Zohocorp Manageengine Opmanager
A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168.
network
low complexity
zohocorp CWE-611
5.4
2023-03-06 CVE-2023-26600 Unspecified vulnerability in Zohocorp products
ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and Asset Explorer through 6987 allow privilege escalation via query reports.
network
low complexity
zohocorp
6.5