4.3
CVSSv2

CVE-2015-0866

Published: 02/02/2015 Updated: 09/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Zoho ManageEngine SupportCenter Plus 7.9 before hotfix 7941 allow remote malicious users to inject arbitrary web script or HTML via the (1) fromCustomer, (2) username, or (3) password parameter to HomePage.do.

Vulnerable Product Search on Vulmon Subscribe to Product

zohocorp manageengine supportcenter plus

Exploits

SupportCenter Plus version 79 suffers from a cross site scripting vulnerability ...