Zoho Manage Engine - XSS (CVE-2018-12998)
22Exploiting IPs reported
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows remote attackers to inject arbitrary web script or HTML via the parameter 'operation' to /servlet/com.adventnet.me.opmanager.servlet.FailOverHelperServlet.
CrowdSec analysis
CVE-2018-12998 is a reflected cross-site scripting (XSS) vulnerability found in multiple Zoho ManageEngine products, including OpManager and related components. This flaw allows remote attackers to inject arbitrary web script or HTML by manipulating certain parameters in requests to the application’s servlet.
CrowdSec has been tracking this vulnerability and its exploits since 3rd of April 2025.
Based on data from the CrowdSec network, nearly all observed exploitation of CVE-2018-12998 is fully opportunistic, with attackers indiscriminately scanning the entire internet. These attacks are automated and lack any form of target selection or reconnaissance. Data from the CrowdSec community also indicates a gradual decrease in attacks targeting CVE-2018-12998. While still present in the wild, exploitation levels have dropped noticeably week-over-week. This may signal that the vulnerability is becoming less relevant or that defenses are improving fast enough for attackers to lose interest.
Exploitation attempts are generally identifiable through requests directed at URLs containing /servlet/com.adventnet.me.opmanager.servlet.failoverhelperservlet
.
Exploitation
Get real-time information about exploitation attempts and actors involved.
Common Weakness Enumeration (CWE)
Protection
Find out relevant information to protect your stack against this CVE.
Blocklist
With our advanced worldwide network detection, CrowdSec can provide a list of IPs known for exploiting the vulnerability.
To increase your protection against this CVE, block exploitation attempts with this list of identified actors.