Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD.
| Software | From | Fixed in |
|---|---|---|
| zohocorp / manageengine_applications_manager | 15.1-15100 | 15.1-15100.x |
| zohocorp / manageengine_applications_manager | 15.1-15110 | 15.1-15110.x |
| zohocorp / manageengine_applications_manager | 15.1-15120 | 15.1-15120.x |
| zohocorp / manageengine_applications_manager | 15.1 | 15.1.x |
| zohocorp / manageengine_applications_manager | - | 15.1 |