Record summary

CVE-2018-12998 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows remote attackers to inject arbitrary web script or HTML via the parameter 'operation' to /servlet/com.adventnet.me.opmanager.servlet.FailOverHelperServlet.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 11, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMZoho manageengine - Cross-Site ScriptingCVSS 6.1

Zoho manageengine is vulnerable to reflected cross-site scripting. This impacts Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 via the parameter 'operation' to /servlet/com.adventnet.me.opmanager.servlet.FailOverHelperServlet.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the affected user's browser, potentially leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Apply the latest security patch or update provided by Zoho ManageEngine to fix the XSS vulnerability.

WeaknessesCWE-79
Authorspikpikcu
Template tagscvecve2018zohoxssmanageenginepacketstormzohocorpvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:zohocorp:firewall_analyzer:-:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

5