CVE

CVE-2018-16965

CVE-2018-16965

In Zoho ManageEngine SupportCenter Plus 8.1.0, there is HTML Injection and Stored XSS via the /ServiceContractDef.do contractName parameter.

Source: CVE-2018-16965

Exit mobile version