CVE-2018-10076Cross-site Scripting in Manageengine Eventlog Analyzer

Severity
6.1MEDIUMNVD
EPSS
0.5%
top 33.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 2
Latest updateMay 14

Description

An issue was discovered in Zoho ManageEngine EventLog Analyzer 11.12. A Cross-Site Scripting vulnerability allows a remote attacker to inject arbitrary web script or HTML via the search functionality (the search box of the Dashboard).

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-4jw3-6wgx-w4c7: An issue was discovered in Zoho ManageEngine EventLog Analyzer 112022-05-14
CVEList
CVE-2018-10076: An issue was discovered in Zoho ManageEngine EventLog Analyzer 112018-07-02
CVE-2018-10076 — Cross-site Scripting | cvebase