Medium severity6.1NVD Advisory· Published Jun 29, 2018· Updated Jun 17, 2026
CVE-2018-12996
CVE-2018-12996
Description
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager before 13 (Build 13800) allows remote attackers to inject arbitrary web script or HTML via the parameter 'method' to GraphicalView.do.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <13.0.0
- Range: <13 (Build 13800)
Patches
Vulnerability mechanics
References
6- packetstormsecurity.com/files/148635/Zoho-ManageEngine-13-13790-build-XSS-File-Read-File-Deletion.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2018/Jul/71nvdExploitMailing ListThird Party Advisory
- github.com/unh3x/just4cve/issues/7nvdExploitThird Party Advisory
- www.cnnvd.org.cn/web/xxk/ldxqById.tagnvdThird Party Advisory
- www.manageengine.com/products/applications_manager/issues.htmlnvdVendor Advisory
- www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2018-12996.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.