CVE-2023-28341

Severity
6.1MEDIUM
EPSS
82.9%
top 0.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 11

Description

Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
CVEList
CVE-2023-28341: Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malic2023-04-11
GHSA
GHSA-34mm-8vxq-7m2j: Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malic2023-04-11
CVE-2023-28341 (MEDIUM CVSS 6.1) | Stored Cross site scripting (XSS) v | cvebase.io