SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-12998

A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before…

MEDIUM 6.1EPSS 99.3%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 99.3%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows remote attackers to inject arbitrary web script or HTML via the parameter 'operation' to /servlet/com.adventnet.me.opmanager.servlet.FailOverHelperServlet.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
99.29% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
zohocorp/firewall analyzer · zohocorp/manageengine netflow analyzer · zohocorp/manageengine network configuration manager · zohocorp/manageengine opmanager · zohocorp/manageengine oputils
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.