Search Results (Refine Search)
- Keyword (text search): cpe:2.3:a:zohocorp:manageengine_applications_manager:16.1:build16135:*:*:*:*:*:*
- CPE Name Search: true
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2024-5678 |
Zohocorp ManageEngine Applications Manager versions 170900 and below are vulnerable to the authenticated admin-only SQL Injection in the Create Monitor feature. Published: August 01, 2024; 3:15:03 AM -0400 |
V4.0:(not available) V3.1: 4.7 MEDIUM V2.0:(not available) |
CVE-2023-38333 |
Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in. Published: August 10, 2023; 5:15:10 PM -0400 |
V4.0:(not available) V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2023-29442 |
Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS. Published: April 26, 2023; 5:15:08 PM -0400 |
V4.0:(not available) V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2023-28341 |
Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page. Published: April 10, 2023; 9:15:07 PM -0400 |
V4.0:(not available) V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2023-28340 |
Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack. Published: April 10, 2023; 9:15:07 PM -0400 |
V4.0:(not available) V3.1: 6.5 MEDIUM V2.0:(not available) |