CVE-2010-3274
Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in the Employee Search Engine in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 allow remote attackers to inject arbitrary web script or HTML via the searchString…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 21.0%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in the Employee Search Engine in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 allow remote attackers to inject arbitrary web script or HTML via the searchString parameter in a (1) showList or (2) Search action.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 21.00% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- zohocorp/manageengine adselfservice plus
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/43241Vendor Advisory
- http://securityreason.com/securityalert/8089
- http://www.coresecurity.com/content/zoho-manageengine-vulnerabilitiesExploit
- http://www.osvdb.org/70871Exploit
- http://www.osvdb.org/70872Exploit
- http://www.securityfocus.com/archive/1/516396/100/0/threaded
- http://www.securityfocus.com/bid/46331Exploit
- http://www.vupen.com/english/advisories/2011/0392Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65349
- http://secunia.com/advisories/43241Vendor Advisory
- http://securityreason.com/securityalert/8089
- http://www.coresecurity.com/content/zoho-manageengine-vulnerabilitiesExploit
- http://www.osvdb.org/70871Exploit
- http://www.osvdb.org/70872Exploit
- http://www.securityfocus.com/archive/1/516396/100/0/threaded
- http://www.securityfocus.com/bid/46331Exploit
- http://www.vupen.com/english/advisories/2011/0392Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65349
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.