← Vulnerability feed

Vulnerability record · CVE-2023-28341 · published 11 April 2023

CVE-2023-28341: Zoho ManageEngine Applications Manager stored XSS on login error page

Zohocorp · Manageengine Applications Manager

Zoho ManageEngine Applications Manager through build 16340 contains a stored cross-site scripting flaw on the incorrect login details page. An unauthenticated attacker can inject malicious JavaScript that is stored and later executed in a victim's browser. Because the script runs in the application's origin, it can act with the victim's session context.

6.1 CVSS 3.1 Medium EPSS 99% · top 0.1% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
99%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw is unauthenticated to inject and EPSS is extremely high, though it requires victim interaction and is not in KEV.

What it is

Zoho ManageEngine Applications Manager through build 16340 contains a stored cross-site scripting flaw on the incorrect login details page. An unauthenticated attacker can inject malicious JavaScript that is stored and later executed in a victim's browser. Because the script runs in the application's origin, it can act with the victim's session context.

Impact

An attacker can execute arbitrary JavaScript in the browser of a user who views the poisoned login error page, potentially stealing session data or performing actions as that user. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.

Attack surface

Reachable over the network via the incorrect login details page with no authentication required to inject, but exploitation requires a victim to view the crafted page (UI:R). No user interaction is needed for the injection itself, only for the payload to fire.

Exploitation

Not listed in CISA KEV and no public exploit references are provided, but EPSS is very high (0.987 probability, 99.9th percentile), indicating elevated likelihood of exploitation activity. The vendor advisory is tagged Patch, so a fix exists.

What to do

  • Apply the vendor security update for CVE-2023-28341 (upgrade past build 16340) as the primary action.
  • If immediate patching is not possible, restrict network access to the Applications Manager login interface to trusted management networks.
  • Deploy a WAF rule to block script payloads submitted to the login error handling endpoint.
  • Review and sanitize output encoding on the incorrect login details page if customizing the application.
  • Monitor vendor advisories for updated builds and re-verify the installed version.

Detection

  • Search web and application logs for requests to the login endpoint containing script tags or JavaScript event handlers in submitted parameters.
  • Monitor for anomalous outbound requests or cookie exfiltration originating from browsers accessing the Applications Manager login page.
  • Alert on unexpected changes to stored login error content or database entries tied to the login page.
  • Correlate repeated failed login attempts followed by script-like payloads in request bodies.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-28341 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-24743Zohocorp manageengine applications manager vulnerabilityAn issue was found in /showReports.do Zoho ManageEngine Applications Manager up to 14550, allows attackers to gain escalated privileges via the resou…EPSS 2.8%9.8CVE-2020-27995Zohocorp manageengine applications manager sql injection vulnerabilitySQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do templa…EPSS 8.8%9.8CVE-2020-15533Zohocorp manageengine applications manager sql injection vulnerabilityIn Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to un…EPSS 4.2%9.8CVE-2020-15394Zohocorp manageengine applications manager sql injection vulnerabilityThe REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a crafted request, leading to R…EPSS 7.9%9.8CVE-2019-19649Zohocorp manageengine applications manager sql injection vulnerabilityZoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the S…EPSS 9.5%9.8CVE-2019-11469Zohocorp manageengine applications manager sql injection vulnerabilityZoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user …EPSS 17%9.8CVE-2019-11448Zohocorp manageengine applications manager sql injection vulnerabilityAn issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the …EPSS 12%9.8CVE-2018-15168Zohocorp manageengine applications manager sql injection vulnerabilityA SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids parameter in a /editDisplayna…EPSS 3.9%

Source: NIST National Vulnerability Database (record CVE-2023-28341), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.