
ZOHO Manage Engine Application Manager - XSS POC

Reflected XSS in ManageEngine Application Manager (13 Build 13970) and prior


Fix Reference

Stored XSS in ManageEngine Application Manager (13 Build 13970) and prior

This version of Application Manager is vulnerable to a stored XSS via the "name" field in the "New Dashboard" and "New Business Dashboards" creation screens that'll be reflected in the "title" of the dashboards.


It's also vulnerable to a stored XSS reflected in the "showapplication" page via the "name" and "description" fields when creating/modifying a monitor group.

Fix Reference

Reflected XSS in ManageEngine Application Manager (13 Build 13980) and prior

The "resourceid" parameter is not santized and is reflecting any code being sent.


Fix Reference