Unrated severityNVD Advisory· Published Jun 9, 2015· Updated May 6, 2026
CVE-2015-2960
CVE-2015-2960
Description
Cross-site scripting (XSS) vulnerability in Zoho NetFlow Analyzer build 10250 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected products
1- cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:-:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- support.zoho.com/portal/manageengine/helpcenter/articles/vulnerability-fix-for-fails-to-restrict-access-permissions-cross-site-scripting-cross-site-request-forgery-over-build-10250nvdPatchVendor Advisory
- jvn.jp/en/jp/JVN98447310/index.htmlnvdVendor Advisory
- jvndb.jvn.jp/jvndb/JVNDB-2015-000074nvdVendor Advisory
- www.securityfocus.com/bid/75071nvd
- www.securitytracker.com/id/1032516nvd
News mentions
0No linked articles in our index yet.