CVE-2025-41437 MEDIUM

CVE-2025-41437: Reflected XSS

Vendor Manageengine
Product OpManager
Weakness CWE-79 · XSS
Published June 9, 2025
Last update June 9, 2025

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Zohocorp ManageEngine OpManager, NetFlow Analyzer, Network Configuration Manager, Firewall Analyzer and OpUtils versions 128565 and below are vulnerable to Reflected XSS on the login page.

Key dates

02Disclosure timeline

June 9, 2025 CVE published
June 9, 2025 Record updated