CVE-2018-16965

Publication date

2018-09-21 17:00:00

Family

mitre

State

PUBLISHED

Description

In Zoho ManageEngine SupportCenter Plus before 8.1 Build 8109, there is HTML Injection and Stored XSS via the /ServiceContractDef.do contractName parameter.