Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-3349 | In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has the ability to add a widget on any dashboard. This widget can be a "Utility Widget" with a "Custom HTML or Text" field. Once this widget is created, it will be loaded on the dashboard where it was added. An attacker can abuse this functionality by creating a "Utility Widget" that contains malicious JavaScript code, aka XSS. |
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T18:19:38.704Z
Reserved: 2017-07-29T00:00:00.000Z
Link: CVE-2017-11739
No data.
Status : Modified
Published: 2019-05-23T16:29:08.213
Modified: 2026-06-17T01:02:17.283
Link: CVE-2017-11739
No data.
OpenCVE Enrichment
No data.
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
EUVD