CVE-2023-38331Cross-site Scripting in Manageengine Supportcenter Plus

Severity
5.4MEDIUMNVD
EPSS
3.7%
top 12.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 28

Description

Zoho ManageEngine Support Center Plus 14001 and below is vulnerable to stored XSS in the products module.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages1 packages

🔴Vulnerability Details

2
CVEList
CVE-2023-38331: Zoho ManageEngine Support Center Plus 14001 and below is vulnerable to stored XSS in the products module2023-07-28
GHSA
GHSA-367m-r4wp-v752: Zoho ManageEngine Support Center Plus 14001 and below is vulnerable to stored XSS in the products module2023-07-28
CVE-2023-38331 — Cross-site Scripting | cvebase