VulnerabilityModified
CVE-2017-11686
Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote attackers to obtain an authenticated user's password via XSS vulnerabilities or sniffing non-SSL traffic on the network, because the password is represented in a cookie with a reversible…
MEDIUM 6.1EPSS 2.29%
Does this matter?
Lower severity and a low EPSS score (2.29%). Track it; it rarely justifies an emergency change on its own.
Description
Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote attackers to obtain an authenticated user's password via XSS vulnerabilities or sniffing non-SSL traffic on the network, because the password is represented in a cookie with a reversible encoding method.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 2.29% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- zohocorp/manageengine eventlog analyzer
- Source
- cve@mitre.org
References
- http://init6.me/exploiting-manageengine-eventlog-analyzer.htmlExploit, Technical Description, Third Party Advisory
- http://init6.me/exploiting-manageengine-eventlog-analyzer.htmlExploit, Technical Description, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.