CVE-2019-12596

MEDIUM

ManageEngine AssetExplorer - Stored Cross-Site Scripting via SoftwareListView.do swType or swComplianceType Parameter

Title source: llm
STIX 2.1

Description

An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via SoftwareListView.do with the parameter swType or swComplianceType.

Scores

CVSS v3 6.1
EPSS 0.0218
EPSS Percentile 80.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
zohocorp/manageengine_assetexplorer 6.5 (6 CPE variants)
Published Jul 11, 2019
Tracked Since Feb 18, 2026