VulnerabilityModified
CVE-2023-23078
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via the comment field when changing the credentials in the Assets.
MEDIUM 6.1EPSS 2.81%
Does this matter?
Lower severity and a low EPSS score (2.81%). Track it; it rarely justifies an emergency change on its own.
Description
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via the comment field when changing the credentials in the Assets.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 2.81% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- zohocorp/manageengine servicedesk plus
- Source
- cve@mitre.org
References
- https://bugbounty.zohocorp.com/bb/#/bug/101000006458675?tab=originatorNot Applicable, Vendor Advisory
- https://www.manageengine.com/products/service-desk/CVE-2023-23078.html
- https://bugbounty.zohocorp.com/bb/#/bug/101000006458675?tab=originatorNot Applicable, Vendor Advisory
- https://www.manageengine.com/products/service-desk/CVE-2023-23078.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.