Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Zoho ManageEngine Log360 before Build 5224 allows stored XSS via the LOGO_PATH key value in the logon settings.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ZOHO ManageEngine Log360 跨站脚本漏洞
Vulnerability Description
ZOHO ManageEngine Log360是美国卓豪(ZOHO)公司的一个集成的日志管理和 Active Directory 审计和警报解决方案。该解决方案可帮助您减轻安全威胁、发现持续的攻击企图、检测可疑的用户活动并遵守监管要求。 ZOHO ManageEngine Log360 中存在跨站脚本漏洞,该漏洞源于产品设置页面的LOGO_PATH字段未能校验客户端数据的有效性。攻击者可通过该漏洞执行客户端代码。以下产品及版本受到影响:Zoho ManageEngine Log360 Build 5
CVSS Information
N/A
Vulnerability Type
N/A