VYPR
Medium severity6.1NVD Advisory· Published Apr 11, 2023· Updated Jun 17, 2026

CVE-2023-28341

CVE-2023-28341

Description

Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

9
  • cpe:2.3:a:zohocorp:manageengine_applications_manager:*:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:a:zohocorp:manageengine_applications_manager:*:*:*:*:*:*:*:*range: >=16.0,<16.3
    • cpe:2.3:a:zohocorp:manageengine_applications_manager:15.9:build15990:*:*:*:*:*:*
    • cpe:2.3:a:zohocorp:manageengine_applications_manager:16.3:build16300:*:*:*:*:*:*
    • cpe:2.3:a:zohocorp:manageengine_applications_manager:16.3:build16310:*:*:*:*:*:*
    • cpe:2.3:a:zohocorp:manageengine_applications_manager:16.3:build16320:*:*:*:*:*:*
    • cpe:2.3:a:zohocorp:manageengine_applications_manager:16.3:build16330:*:*:*:*:*:*
    • cpe:2.3:a:zohocorp:manageengine_applications_manager:16.3:build16340:*:*:*:*:*:*
  • Zoho/ManageEngine Applications Managerdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.