An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.
The product does not properly verify that the source of data or communication is valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Manageengine_network_configuration_manager | Zohocorp | 12.6-build126165 (including) | 12.6-build126165 (including) |