nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-38870 CVE-2024-38870
LOW
Stored XSS
Record summary
CVE-2024-38870 has a selected CVSS score of 3.5 (low).
Description
Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and OpManager Enterprise Edition versions before 128104, from 128151 before 128238, from 128247 before 128250 are vulnerable to Stored XSS vulnerability in reports module.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 23, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
OpManager, OpManager Plus, OpManager MSP, OpManager Enterprise EditionBrowse ManageEngine / OpManager, OpManager Plus, OpManager MSP, OpManager Enterprise EditionDefault status: unaffected | CVE List | Before 128104 | affected |
| 128151 to < 128238 | affected | ||
| 128247 to < 128250 | affected |
References
2manageengine.com
https://www.manageengine.com/network-monitoring/security-updates/cve-2024-38870.html