Vulnerability record · CVE-2023-28341 · published 11 April 2023
CVE-2023-28341: Zoho ManageEngine Applications Manager stored XSS on login error page
Zohocorp · Manageengine Applications Manager
Zoho ManageEngine Applications Manager through build 16340 contains a stored cross-site scripting flaw on the incorrect login details page. An unauthenticated attacker can inject malicious JavaScript that is stored and later executed in a victim's browser. Because the script runs in the application's origin, it can act with the victim's session context.
Description
Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityThe flaw is unauthenticated to inject and EPSS is extremely high, though it requires victim interaction and is not in KEV.
What it is
Zoho ManageEngine Applications Manager through build 16340 contains a stored cross-site scripting flaw on the incorrect login details page. An unauthenticated attacker can inject malicious JavaScript that is stored and later executed in a victim's browser. Because the script runs in the application's origin, it can act with the victim's session context.
Impact
An attacker can execute arbitrary JavaScript in the browser of a user who views the poisoned login error page, potentially stealing session data or performing actions as that user. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.
Attack surface
Reachable over the network via the incorrect login details page with no authentication required to inject, but exploitation requires a victim to view the crafted page (UI:R). No user interaction is needed for the injection itself, only for the payload to fire.
Exploitation
Not listed in CISA KEV and no public exploit references are provided, but EPSS is very high (0.987 probability, 99.9th percentile), indicating elevated likelihood of exploitation activity. The vendor advisory is tagged Patch, so a fix exists.
What to do
- Apply the vendor security update for CVE-2023-28341 (upgrade past build 16340) as the primary action.
- If immediate patching is not possible, restrict network access to the Applications Manager login interface to trusted management networks.
- Deploy a WAF rule to block script payloads submitted to the login error handling endpoint.
- Review and sanitize output encoding on the incorrect login details page if customizing the application.
- Monitor vendor advisories for updated builds and re-verify the installed version.
Detection
- Search web and application logs for requests to the login endpoint containing script tags or JavaScript event handlers in submitted parameters.
- Monitor for anomalous outbound requests or cookie exfiltration originating from browsers accessing the Applications Manager login page.
- Alert on unexpected changes to stored login error content or database entries tied to the login page.
- Correlate repeated failed login attempts followed by script-like payloads in request bodies.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://manageengine.com | Product |
| https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2023-28341.html | PatchVendor Advisory |
| https://manageengine.com | Product |
| https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2023-28341.html | PatchVendor Advisory |
Track CVE-2023-28341 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-28341), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.