CVE-2025-7473
MEDIUMZohocorp ManageEngine EndPoint Central <11.4.2516.1 - XML Injection
Title source: llmDescription
Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection.
Scores
CVSS v3
5.2
EPSS
0.0003
EPSS Percentile
7.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-91
Status
published
Products (1)
zohocorp/manageengine_endpoint_central
< 11.4.2516.01
Published
Oct 21, 2025
Tracked Since
Feb 18, 2026