Zohocorp ManageEngine Applications Manager
cpe:2.3:a:zohocorp:manageengine_applications_manager:*:*:*:*:*:*:*
- <= 176600
A stored cross-site scripting vulnerability has been identified in ManageEngine Applications Manager versions through 176600. This issue arises in the File/Directory monitor when content checking is enabled, allowing malicious JavaScript to be executed in the context of an administrator user.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected malicious content is executed in the victim's browser, potentially leading to unauthorized actions within the Applications Manager as an administrator.
Users can update to ManageEngine Applications Manager version 176700 or later, which addresses the vulnerability by implementing proper encoding. Instructions for updating are available on the ManageEngine website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.