Learn about CVE-2018-12996, a Cross-Site Scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager allowing remote attackers to insert unauthorized web script or HTML code.
Zoho ManageEngine Applications Manager prior to version 13 (Build 13800) has a Cross-Site Scripting (XSS) vulnerability that allows remote attackers to insert unauthorized web script or HTML code.
Understanding CVE-2018-12996
This CVE involves a reflected XSS vulnerability in Zoho ManageEngine Applications Manager.
What is CVE-2018-12996?
The vulnerability in Zoho ManageEngine Applications Manager allows remote attackers to inject arbitrary web script or HTML via the 'method' parameter in GraphicalView.do.
The Impact of CVE-2018-12996
Technical Details of CVE-2018-12996
This section provides technical details of the vulnerability.
Vulnerability Description
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager before version 13 (Build 13800) allows remote attackers to inject arbitrary web script or HTML via the 'method' parameter to GraphicalView.do.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Protect your systems from this vulnerability with the following steps:
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates