CVE-2017-11739
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has the ability to add a widget on any dashboard. This widget can be a "Utility Widget" with a "Custom HTML or Text" field. Once this widget is created, it will be loaded on the dashboard where it was added. An attacker can abuse this functionality by creating a "Utility Widget" that contains malicious JavaScript code, aka XSS.
En Zoho ManageEngine Application Manager 13.1 Build 13100, un usuario autenticado, con privilegios administrativos, tiene la facultad de agregar un widget en cualquier panel. Este widget puede ser un "Utility Widget" con un campo "Custom HTML or Text". Una vez que este widget sea creado, será cargado en el panel donde fue agregado. Un atacante puede abusar de esta funcionalidad mediante la creación de un "Utility Widget" que contenga un código JavaScript malicioso, también conocido como XSS.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-07-29 CVE Reserved
- 2019-05-23 CVE Published
- 2024-05-16 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://application.com | Not Applicable | |
http://www.securityfocus.com/bid/108469 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=18734 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://manageengine.com | 2019-05-27 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zohocorp Search vendor "Zohocorp" | Manageengine Applications Manager Search vendor "Zohocorp" for product "Manageengine Applications Manager" | 13.1 Search vendor "Zohocorp" for product "Manageengine Applications Manager" and version "13.1" | 13100 |
Affected
|