Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2023-23077PUBLISHED: 2023-02-01Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 13 via the comment field when adding a new status comment.
CVE-2023-23078PUBLISHED: 2023-02-01Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via the comment field when changing the credentials in the Assets.
CVE-2023-22287PUBLISHED: 2023-02-01** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.
CVE-2023-23073PUBLISHED: 2023-02-01Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via PO in the purchase component.
CVE-2023-23074PUBLISHED: 2023-02-01Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via embedding videos in the language component.
User Rank: Apprentice
1/13/2020 | 9:25:26 AM
This is aligned with the trend- the proliferating IoT scene is where hackers are finding the blind spot of the enterprise and consumer.
Some hacks here are "for shows" but some clearly indicate the risk of product security- it provides access into the data center and it can impact life and business continuity