ManageEngine – Mobile Device Manager Plus – XSS Vulnerability in the Product Login Screen

Mobile Device Manager Plus MSP has fixed a cross-site scripting (XSS) vulnerability recently detected by Ken Pyle, in it’s latest update. This vulnerability allowed a user to view the cookies by running a param on the product login page.

The security fix is available in build # 92698 and above. You can download the latest build from here.

Follow #mdm-security for all security related updates on Mobile Device Manager Plus MSP.