// For flags

CVE-2018-9163

ManageEngine Recovery Manager Plus 5.3 - Cross-Site Scripting

Severity Score

5.4
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A stored Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Recovery Manager Plus before 5.3 (Build 5350) allows remote authenticated users (with Add New Technician permissions) to inject arbitrary web script or HTML via the loginName field to technicianAction.do.

Una vulnerabilidad Cross-Site Scripting (XSS) persistente almacenada en Zoho ManageEngine Recovery Manager Plus en versiones anteriores 5.3 (Build 5350) permite que los usuarios autenticados remotos (con permisos Add New Technician) inyecten scripts web o HTML arbitrarios a través del campo loginName en technicianAction.do.

ManageEngine Recovery Manager Plus versions 5.3 and below suffer from a persistent cross site scripting vulnerability.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-03-31 CVE Reserved
  • 2018-04-02 CVE Published
  • 2023-08-24 EPSS Updated
  • 2024-08-05 CVE Updated
  • 2024-08-05 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Zohocorp
Search vendor "Zohocorp"
Manageengine Recovery Manager Plus
Search vendor "Zohocorp" for product "Manageengine Recovery Manager Plus"
< 5.3
Search vendor "Zohocorp" for product "Manageengine Recovery Manager Plus" and version " < 5.3"
-
Affected