peter bassill · operator
$ cve CVE-2018-9163 JSON

CVE-2018-9163 EXPLOIT

5.4
MEDIUM · CVSS 3.0 · EPSS 4.8% (pctl 92)

Patch early

A public exploit exists.

Description

A stored Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Recovery Manager Plus before 5.3 (Build 5350) allows remote authenticated users (with Add New Technician permissions) to inject arbitrary web script or HTML via the loginName field to technicianAction.do.

Scoring

CVSS5.4 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS4.8% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2018-04-02
Last modified2026-06-17

Affected (1)

VendorProduct
zohocorpmanageengine recovery manager plus

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD