I. VULNERABILITY ------------------------- Zoho ManageEngine OpManager 12.3 before Build 123223 has XSS via the updateWidget API. II. CVE REFERENCE ------------------------- CVE-2018-19288 III. VENDOR ------------------------- https://www.manageengine.com IV. TIMELINE ------------------------- 17/10/18 Vulnerability discovered 18/10/18 Vendor contacted 18/11/2018 OPManager replay that they fixed V. CREDIT ------------------------- Murat Aydemir from Biznet Bilisim A.S. VI. DESCRIPTION ------------------------- ManageEngine OPManager product(version 12.3) was vulnerable to stored xss attacks. A successfully exploit of this attack could allow thief users sessions or arbitrary interpret javascript code on remote host. References: https://www.manageengine.com/network-monitoring/help/read-me.html, https://bugbounty.zoho.com/bb/info#hof VII. Remediation ------------------------- Its recommended to update latest version of OPManager. https://www.manageengine.com/network-monitoring/download.html