CVE-2023-23074

MEDIUM

ManageEngine ServiceDesk Plus 14 - Stored Cross-Site Scripting via Video Embedding in Language Component

Title source: llm
STIX 2.1

Description

Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via embedding videos in the language component.

Scores

CVSS v3 6.1
EPSS 0.7087
EPSS Percentile 98.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
zohocorp/manageengine_servicedesk_plus 14.0 (8 CPE variants)
Published Feb 01, 2023
Tracked Since Feb 18, 2026