CVE-2023-23078

MEDIUM

Zoho ManageEngine ServiceDesk Plus 14 - Stored Cross-Site Scripting via Assets Comment Field

Title source: llm
STIX 2.1

Description

Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via the comment field when changing the credentials in the Assets.

Scores

CVSS v3 6.1
EPSS 0.2621
EPSS Percentile 96.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
zohocorp/manageengine_servicedesk_plus 14.0 (8 CPE variants)
Published Feb 01, 2023
Tracked Since Feb 18, 2026