CVE-2018-12996

MEDIUM

ManageEngine Applications Manager < 13 - Reflected Cross-Site Scripting via GraphicalView.do Method Parameter

Title source: llm
STIX 2.1

Description

A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager before 13 (Build 13800) allows remote attackers to inject arbitrary web script or HTML via the parameter 'method' to GraphicalView.do.

References (6)

Core 6
Core References
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2018/Jul/71
Exploit, Third Party Advisory x_refsource_misc
https://github.com/unh3x/just4cve/issues/7

Scores

CVSS v3 6.1
EPSS 0.0145
EPSS Percentile 81.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
zohocorp/manageengine_applications_manager < 13
Published Jun 29, 2018
Tracked Since Feb 18, 2026