CVE-2018-10803
10.05.2018, 14:29
Cross-site scripting (XSS) vulnerability in the add credentials functionality in Zoho ManageEngine NetFlow Analyzer v12.3 before 12.3.125 (build 123125) allows remote attackers to inject arbitrary web script or HTML via a crafted description value. This can be exploited through CSRF.
Vendor | Product | Version |
---|---|---|
zohocorp | manageengine_netflow_analyzer | 12.3 ≤ 𝑥 < 12.3.125 |
𝑥
= Vulnerable software versions