CVE-2018-17596: Zohocorp ManageEngine Assetexplorer

Medium severity, CVSS 6.1. EPSS: 2.3% chance of exploitation in the next 30 days.

In Zoho ManageEngine AssetExplorer, a Stored XSS vulnerability was discovered in the 6.2.0 version via the /AssetDef.do ciName or assetName parameter.

Affected products

  • Zohocorp ManageEngine Assetexplorer: version 6.2.0 only

Published 2018-10-02. Last modified 2026-06-17.