Zoho ManageEngine Key Manager Plus prior to 6001 allows Stored XSS on the user-management page while importing malicious user details from AD.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
zohocorp manageengine key manager plus |
||
zohocorp manageengine key manager plus 6.0 |