{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-38870","assignerOrgId":"0fc0942c-577d-436f-ae8e-945763c79b02","state":"PUBLISHED","assignerShortName":"ManageEngine","dateReserved":"2024-06-20T13:15:39.620Z","datePublished":"2024-07-17T16:48:58.815Z","dateUpdated":"2024-08-02T04:19:20.403Z"},"containers":{"cna":{"affected":[{"collectionURL":"https://www.manageengine.com/network-monitoring/","defaultStatus":"unaffected","product":"OpManager, OpManager Plus, OpManager MSP, OpManager Enterprise Edition","vendor":"ManageEngine","versions":[{"lessThan":"128104","status":"affected","version":"0","versionType":"128104"},{"lessThan":"128238","status":"affected","version":"128151","versionType":"128238"},{"lessThan":"128250","status":"affected","version":"128247","versionType":"128250"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and OpManager Enterprise Edition versions before 128104, from 128151 before 128238, from 128247 before 128250 are vulnerable to Stored XSS vulnerability in reports module."}],"value":"Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and OpManager Enterprise Edition versions before 128104, from 128151 before 128238, from 128247 before 128250 are vulnerable to Stored XSS vulnerability in reports module."}],"impacts":[{"capecId":"CAPEC-592","descriptions":[{"lang":"en","value":"CAPEC-592 Stored XSS"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":3.5,"baseSeverity":"LOW","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-79","description":"CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"0fc0942c-577d-436f-ae8e-945763c79b02","shortName":"ManageEngine","dateUpdated":"2024-07-17T16:48:58.815Z"},"references":[{"url":"https://www.manageengine.com/network-monitoring/security-updates/cve-2024-38870.html"}],"source":{"discovery":"UNKNOWN"},"title":"Stored XSS","x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-07-23T14:46:16.424061Z","id":"CVE-2024-38870","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-07-23T14:46:29.833Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T04:19:20.403Z"},"title":"CVE Program Container","references":[{"url":"https://www.manageengine.com/network-monitoring/security-updates/cve-2024-38870.html","tags":["x_transferred"]}]}]}}