VendorsZoho Corpmanageengine_adselfservice_plus4.5
Vulnerabilities

Zoho Corp ManageEngine ADSelfService Plus 4.5

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2021-28958
Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.
Published 2021-06-25 · Modified
9.8EPSS 0.731
CVE-2023-28342
Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.
Published 2023-04-05 · Modified
7.5EPSS 0.783
CVE-2018-20485
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature.
Published 2018-12-26 · Modified
6.11 PoCEPSS 0.053
CVE-2011-5105
Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in ZOHO ManageEngine ADSelfService Plus 4.5 Build 4521 allow remote attackers to inject arbitrary web script or HTML via the (1) searchType and (2) searchString parameters, a different vulnerability than CVE-2010-3274.
Published 2012-08-23 · Modified
4.31 PoCEPSS 0.060