XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone “/netflow/jspui/linkdownalertConfig.jsp” file in the task parameter.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7425
Reference (s):
- FULLDISC:20190206 [CVE-2019-7422, CVE-2019-7423, CVE-2019-7424, CVE-2019-7425, CVE-2019-7426, CVE-2019-7427] Cross Site Scripting in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 Administration zone
- URL: http://seclists.org/fulldisclosure/2019/Feb/29
- http://packetstormsecurity.com/files/151585/Zoho-ManageEngine-Netflow-Analyzer-Professional-7.0.0.2-XSS.html
- https://www.manageengine.com/products/netflow/?doc

