CVE ID : CVE-2023-23078
Product Name | Severity | Affected Version(s) | Fixed Version | Fixed On |
---|---|---|---|---|
ServiceDesk Plus | Medium | 14102 and below | 14103 | Dec. 23, 2022 |
ServiceDesk Plus MSP | Medium | 13004 and below | 14000 | Jan. 23, 2023 |
AssetExplorer | Medium | 6986 and below | 6987 | Dec. 23, 2022 |
Details
A stored cross-site scripting (XSS) vulnerability allowed users to inject a malicious JavaScript in the asset details page. The script is executed when a user views the asset page.
We fixed the issue by encoding data during client rendering to prevent the JavaScript from being executed.
Impact
The vulnerability can be exploited by threat actors to perform further attacks.
Steps to upgrade
Acknowledgements
This vulnerability was reported by HMs on our bug bounty portal.
If you have any questions or concerns, please contact product support for further details at the below-mentioned email addresses.
ServiceDesk Plus: support@servicedeskplus.com
ServiceDesk Plus MSP: support@servicedeskplusmsp.com
AssetExplorer: assetexplorer-support@manageengine.com