← Back

CVE-2023-28341

nvd nist
Published: Apr 11, 2023Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page.

Affected (7)

1 product
Manageengine Applications Manager
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Zohocorp
From 16.0 to 16.3
Version 15.9 build15990
Version 16.3 build16300
Version 16.3 build16310
Version 16.3 build16320
Version 16.3 build16330
Version 16.3 build16340

References (4)

Source: cve@mitre.org
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Product

Timeline

No history available yet.