Zoho ManageEngine SupportCenter Plus before 11020 allows Stored XSS in the request history.
                
            References
                    | Link | Resource | 
|---|---|
| https://manageengine.com | Vendor Advisory | 
| https://pitstop.manageengine.com/portal/en/community/topic/manageengine-supportcenter-plus-version-11-0-build-11020-released | Release Notes Vendor Advisory | 
| https://raxis.com/blog/cve-2022-25373 | Exploit Third Party Advisory | 
| https://manageengine.com | Vendor Advisory | 
| https://pitstop.manageengine.com/portal/en/community/topic/manageengine-supportcenter-plus-version-11-0-build-11020-released | Release Notes Vendor Advisory | 
| https://raxis.com/blog/cve-2022-25373 | Exploit Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    21 Nov 2024, 06:52
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://manageengine.com - Vendor Advisory | |
| References | () https://pitstop.manageengine.com/portal/en/community/topic/manageengine-supportcenter-plus-version-11-0-build-11020-released - Release Notes, Vendor Advisory | |
| References | () https://raxis.com/blog/cve-2022-25373 - Exploit, Third Party Advisory | 
Information
                Published : 2022-04-05 19:15
Updated : 2024-11-21 06:52
NVD link : CVE-2022-25373
Mitre link : CVE-2022-25373
CVE.ORG link : CVE-2022-25373
JSON object : View
Products Affected
                zohocorp
- manageengine_supportcenter_plus
CWE
                
                    
                        
                        CWE-79
                        
            Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
