← Vulnerability feed

Vulnerability record · CVE-2019-8929 · published 17 May 2019

CVE-2019-8929: Zohocorp manageengine netflow analyzer cross-site scripting vulnerability

Zohocorp · Manageengine Netflow Analyzer

An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/selectDevice.jsp file in these GET parameters: param and rtype.

6.1 CVSS 3.0 Medium EPSS 11% · top 4.2% CWE-79 · Cross-site scripting
6.1CVSS 3.0 base score, v2 4.3
11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/selectDevice.jsp file in these GET parameters: param and rtype.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-8929 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-12196Zoho ManageEngine NetFlow Analyzer SQL injection in compareReportThe compareReport endpoint in Zoho ManageEngine NetFlow Analyzer 12.3 fails to sanitize the DeviceID parameter, allowing SQL injection. An unauthenti…EPSS 69%analysed8.8CVE-2022-38772ManageEngine OpManager and related products NMAP feature RCE via authenticated DB changesMultiple Zoho ManageEngine products (OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, OpUtils) before speci…EPSS 78%analysed8.8CVE-2022-37024Zoho ManageEngine ITOM products allow authenticated database changes leading to RCEMultiple Zoho ManageEngine products (OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, OpUtils, Firewall Ana…EPSS 79%analysed8.6CVE-2023-47211ManageEngine OpManager uploadMib path traversal allows arbitrary file creationThe uploadMib function in ManageEngine OpManager 12.7.258 does not properly validate paths, so a crafted HTTP request carrying a malicious MIB file c…EPSS 47%analysed8.2CVE-2022-35404Zohocorp manageengine opmanager improper input validation vulnerabilityManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a serv…EPSS 2.9%7.8CVE-2019-12133Zohocorp manageengine analytics plus uncontrolled search path element vulnerabilityMultiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory a…EPSS 1.7%7.5CVE-2022-36923Zohocorp manageengine firewall analyzer improper access control vulnerabilityZoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 20…EPSS 7.1%7.5CVE-2018-12997Zohocorp firewall analyzer information exposure vulnerabilityIncorrect Access Control in FailOverHelperServlet in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before bui…EPSS 6.6%

Source: NIST National Vulnerability Database (record CVE-2019-8929), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.