CVE-2014-5103

ManageEngine EventLog Analyzer 9 build 9000 - Cross-Site Scripting via j_username Parameter

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine EventLog Analyzer 9 build 9000 allows remote attackers to inject arbitrary web script or HTML via the j_username parameter to event/j_security_check. Fixed in Version 10 Build 10000.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/532856/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/68854

Scores

EPSS 0.0045
EPSS Percentile 63.7%

Details

CWE
CWE-79
Status published
Products (1)
zohocorp/manageengine_eventlog_analyzer 9.0 9000
Published Jul 25, 2014
Tracked Since Feb 18, 2026