CVE-2023-23077
01.02.2023, 20:15
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 13 via the comment field when adding a new status comment.
| Vendor | Product | Version |
|---|---|---|
| zohocorp | manageengine_servicedesk_plus | 13.0 |
| zohocorp | manageengine_servicedesk_plus | 13.0:13000 |
| zohocorp | manageengine_servicedesk_plus | 13.0:13001 |
| zohocorp | manageengine_servicedesk_plus | 13.0:13002 |
| zohocorp | manageengine_servicedesk_plus | 13.0:13003 |
| zohocorp | manageengine_servicedesk_plus | 13.0:13004 |
| zohocorp | manageengine_servicedesk_plus | 13.0:13005 |
| zohocorp | manageengine_servicedesk_plus | 13.0:13006 |
| zohocorp | manageengine_servicedesk_plus | 13.0:13007 |
| zohocorp | manageengine_servicedesk_plus | 13.0:13008 |
| zohocorp | manageengine_servicedesk_plus | 13.0:13009 |
| zohocorp | manageengine_servicedesk_plus | 13.0:13010 |
| zohocorp | manageengine_servicedesk_plus | 13.0:13011 |
| zohocorp | manageengine_servicedesk_plus | 13.0:13012 |
𝑥
= Vulnerable software versions