Direct Inward Dialing: +1 408 916 9892
Vulnerability details | |
Severity | Medium |
CVE ID | CVE-2023-37308 |
Affected software versions | Builds 7091 and below [How to find your build number?] |
Fixed version | Build 7100 |
Fixed on | December 28, 2022 |
CVE-2023-37308 refers to a XSS vulnerability in username field reported in ManageEngine ADAudit Plus that made it possible for users to inject malicious JavaScript into the username field of the product.
We have released ADAudit Plus build 7100, that fixes the issue by sanitizing the XSS payload.
The vulnerability in ADAudit Plus allows users to inject malicious JavaScript into the username section of certain reports within the product. When the reports are loaded, the injected script will be executed. This type of vulnerability poses a significant risk potentially leading to data exfiltration, system compromise, or other malicious activities.
Upgrade your ADAudit Plus instance to the latest build 7100, using the service pack.
This issue was reported by Ryan through the Zoho BugBounty program.
If you have any questions or need assistance, please get in touch with support@adauditplus.com.