Описание
An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.
Ссылки
- Third Party Advisory
- Release Notes
- Third Party Advisory
- Release Notes
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:zohocorp:manageengine_network_configuration_manager:12.6:build126165:*:*:*:*:*:*
EPSS
Процентиль: 58%
0.00371
Низкий
4.3 Medium
CVSS3
8.8 High
CVSS3
Дефекты
CWE-346
Связанные уязвимости
CVSS3: 4.3
github
больше 2 лет назад
An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.
EPSS
Процентиль: 58%
0.00371
Низкий
4.3 Medium
CVSS3
8.8 High
CVSS3
Дефекты
CWE-346