CVE detail
CVE-2017-11739 — CVE-2017-11739
Published 2019-05-23 · Modified 2026-06-17 · Vendor zohocorp · Product manageengine_applications_manager · Source nvd
MEDIUM
severity
CVSS-derived band
0.0280
EPSS probability
exploitation probability, 30d
85.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has the ability to add a widget on any dashboard. This widget can be a "Utility Widget" with a "Custom HTML or Text" field. Once this widget is created, it will be loaded on the dashboard where it was added. An attacker can abuse this functionality by creating a "Utility Widget" that contains malicious JavaScript code, aka XSS.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References