VendorsZoho Corpmanageengine_adselfservice_plus5.1
Vulnerabilities

Zoho Corp ManageEngine ADSelfService Plus 5.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2019-3905
Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF.
Published 2019-01-03 · Modified
10.0EPSS 0.033
CVE-2021-28958
Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.
Published 2021-06-25 · Modified
9.8EPSS 0.731
CVE-2019-18411
Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally. Attackers could use the reset password function and control the system to send the authentication code back to the channel that the attackers own.
Published 2019-11-06 · Modified
8.8EPSS 0.023
CVE-2023-28342
Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.
Published 2023-04-05 · Modified
7.5EPSS 0.783
CVE-2019-7161
An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.x through build 5704. It uses fixed ciphering keys to protect information, giving the capacity for an attacker to decipher any protected data.
Published 2019-03-18 · Modified
7.5EPSS 0.056
CVE-2018-20485
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature.
Published 2018-12-26 · Modified
6.11 PoCEPSS 0.053
CVE-2019-8346
In Zoho ManageEngine ADSelfService Plus 5.x through 5704, an authorization.do cross-site Scripting (XSS) vulnerability allows for an unauthenticated manipulation of the JavaScript code by injecting the HTTP form parameter adscsrf. An attacker can use this to capture a user's AD self-service password reset and MFA token.
Published 2019-05-24 · Modified
6.1EPSS 0.035
CVE-2019-18781
An open redirect vulnerability was discovered in Zoho ManageEngine ADSelfService Plus 5.x before 5809 that allows attackers to force users who click on a crafted link to be sent to a specified external site.
Published 2019-12-18 · Modified
6.1EPSS 0.018