CVE-2025-9787 Details
Description
Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view.
A stored cross-site scripting vulnerability has been identified in ManageEngine Applications Manager, affecting versions through 177400. This issue arises in the NOC view, where the dashboard search field can be exploited if a dashboard name contains a malicious JavaScript payload. When the payload is executed, it runs in the context of the victim's browser, potentially allowing the attacker to perform actions based on the victim's role in Applications Manager.
Users can update to ManageEngine Applications Manager version 177500 or any version between 177201 and 177209 to address this vulnerability. Instructions for updating are available on the ManageEngine Applications Manager service packs page.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2025-9787.html | ManageEngine | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ManageEngine |
Affected Products
| Product | Versions |
|---|---|
| zohocorp manageengine applications manager | >= 17.4, < 17.7 17.3 build173300 17.3 build173301 17.3 build173302 17.3 build173303 17.3 build173304 17.7 - 17.7 build177000 17.7 build177100 17.7 build177200 17.7 build177201 17.7 build177202 17.7 build177203 17.7 build177204 17.7 build177300 17.7 build177400 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ManageEngine |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 29, 2026 | Initial Analysis | [email protected] |
| Dec 18, 2025 | New CVE Received | ManageEngine |