SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-11560

Thus, an attacker can inject a malicious JavaScript payload inside the HTML file and upload it to the application.

MEDIUM 5.4EPSS 1.39%

Does this matter?

Lower severity and a low EPSS score (1.39%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in ZOHO ManageEngine OpManager 12.2. By adding a Google Map to the application, an authenticated user can upload an HTML file. This HTML file is then rendered in various locations of the application. JavaScript inside the uploaded HTML is also interpreted by the application. Thus, an attacker can inject a malicious JavaScript payload inside the HTML file and upload it to the application.

CVSS 3.0
5.4 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
1.39% probability · 71th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
zohocorp/manageengine opmanager
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.