CVE-2018-9163 EXPLOIT
5.4
MEDIUM · CVSS 3.0 · EPSS 4.8% (pctl 92)
Patch early
A public exploit exists.
Description
A stored Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Recovery Manager Plus before 5.3 (Build 5350) allows remote authenticated users (with Add New Technician permissions) to inject arbitrary web script or HTML via the loginName field to technicianAction.do.
Scoring
| CVSS | 5.4 (MEDIUM, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
| EPSS | 4.8% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-04-02 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| zohocorp | manageengine recovery manager plus |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | ManageEngine Recovery Manager Plus 5.3 - Cross-Site Scripting | 2018-05-21 |
References
- http://www.securityfocus.com/bid/103773
- https://gurelahmet.com/cve-2018-9163-zoho-manageengine-recovery-manager-plus-5-3-build-5330-stored-cross-site-scripting-xss-vulnerability/
- https://www.exploit-db.com/exploits/44666/
- https://www.manageengine.com/ad-recovery-manager/release-notes.html#5350
- http://www.securityfocus.com/bid/103773
- https://gurelahmet.com/cve-2018-9163-zoho-manageengine-recovery-manager-plus-5-3-build-5330-stored-cross-site-scripting-xss-vulnerability/
- https://www.exploit-db.com/exploits/44666/
- https://www.manageengine.com/ad-recovery-manager/release-notes.html#5350
→ the Explorer · watch your stack · NVD