CVE-2018-15169: Zohocorp ManageEngine Applications Manager

Medium severity, CVSS 6.1. EPSS: 1.7% chance of exploitation in the next 30 days.

A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820 allows remote attackers to inject arbitrary web script or HTML via the /deleteMO.do method parameter.

Affected products

  • Zohocorp ManageEngine Applications Manager: before 13.13820 (fixed in 13.13820)

Published 2018-08-08. Last modified 2026-06-17.