Zoho ManageEngine OpManager 12.3 before build 123239 allows XSS in the Notes column of the Alarms section.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://www.manageengine.com/network-monitoring/help/read-me.html | release notes vendor advisory |
http://www.securityfocus.com/bid/106302 | third party advisory vdb entry |