CVE-2018-12998
Zoho firewall_analyzer Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Record summary
CVE-2018-12998 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows remote attackers to inject arbitrary web script or HTML via the parameter 'operation' to /servlet/com.adventnet.me.opmanager.servlet.FailOverHelperServlet.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 11, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
firewall_analyzerBrowse Zoho / firewall_analyzer | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMZoho manageengine - Cross-Site ScriptingCVSS 6.1
Zoho manageengine is vulnerable to reflected cross-site scripting. This impacts Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 via the parameter 'operation' to /servlet/com.adventnet.me.opmanager.servlet.FailOverHelperServlet.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the affected user's browser, potentially leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Apply the latest security patch or update provided by Zoho ManageEngine to fix the XSS vulnerability.
Source: ProjectDiscovery