CVE-2017-11686
Last modified
CVE-2017-11686 is a vulnerability of currently unknown severity. Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote attackers to obtain an authenticated user's password via XSS vulnerabilities or sniffing non-SSL traffic on the network, because the password is represented in a cookie with a reversible encoding method.. EPSS estimates a 2.29% chance of exploitation in the next 30 days.
Description
Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote attackers to obtain an authenticated user's password via XSS vulnerabilities or sniffing non-SSL traffic on the network, because the password is represented in a cookie with a reversible encoding method.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zohocorp | Manageengine Eventlog Analyzer | 11.4 |
| Zohocorp | Manageengine Eventlog Analyzer | 11.5 |
References
- http://init6.me/exploiting-manageengine-eventlog-analyzer.htmlExploit, Technical Description, Third Party Advisory
- http://init6.me/exploiting-manageengine-eventlog-analyzer.htmlExploit, Technical Description, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-11686?
How severe is CVE-2017-11686?
How do I fix CVE-2017-11686?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-11680Cross-Site Request Forgery (CSRF) exists in Hashtopussy 0.4.…
- CVE-2017-11681Incorrect Access Control vulnerability in Hashtopussy 0.4.0 …
- CVE-2017-11682Stored Cross-site scripting vulnerability in Hashtopussy 0.4…6.1
- CVE-2017-11683There is a reachable assertion in the Internal::TiffReader::…6.5
- CVE-2017-11684There is an illegal address access in the build_table functi…
- CVE-2017-11685Multiple Reflective cross-site scripting (XSS) vulnerabiliti…
- CVE-2017-11687Multiple Persistent cross-site scripting (XSS) vulnerabiliti…
- CVE-2017-1169IBM DOORS next Generation (DNG/RRC) is vulnerable to cross-s…
- CVE-2017-11691Cross-site scripting (XSS) vulnerability in auth_profile.php…
- CVE-2017-11692The function "Token& Scanner::peek" in scanner.cpp in yaml-c…
- CVE-2017-11693MEDHOST Document Management System contains hard-coded crede…
- CVE-2017-11694MEDHOST Document Management System contains hard-coded crede…
Are you affected by CVE-2017-11686?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
