CVE-2017-11686

Severity
6.1MEDIUM
EPSS
1.7%
top 17.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 27
Latest updateMay 17

Description

Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote attackers to obtain an authenticated user's password via XSS vulnerabilities or sniffing non-SSL traffic on the network, because the password is represented in a cookie with a reversible encoding method.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-jfmp-88v9-hx9x: Zoho ManageEngine Event Log Analyzer 112022-05-17
CVEList
CVE-2017-11686: Zoho ManageEngine Event Log Analyzer 112017-07-27
CVE-2017-11686 (MEDIUM CVSS 6.1) | Zoho ManageEngine Event Log Analyze | cvebase.io