Description
Multiple cross-site scripting (XSS) vulnerabilities in ZOHO ManageEngine ADManager Plus before 6.2 Build 6270 allow remote attackers to inject arbitrary web script or HTML via the (1) technicianSearchText parameter to the Help Desk Technician page or (2) rolesSearchText parameter to the Help Desk Roles.
References (2)
Core 2
Core References
Exploit x_refsource_misc
http://packetstormsecurity.com/files/130737/Manage-Engine-AD-Audit-Manager-Plus-Cross-Site-Scripting.html
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/534833/100/0/threaded
Scores
EPSS
0.0044
EPSS Percentile
63.4%
Details
CWE
CWE-79
Status
published
Products (1)
zohocorp/manageengine_admanager_plus
< 6.2
Published
Mar 11, 2015
Tracked Since
Feb 18, 2026