VendorsZoho Corpmanageengine_adselfservice_plus5.7
Vulnerabilities

Zoho Corp ManageEngine ADSelfService Plus 5.7

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2019-3905
Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF.
Published 2019-01-03 · Modified
10.0EPSS 0.033
CVE-2021-28958
Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.
Published 2021-06-25 · Modified
9.8EPSS 0.731
CVE-2018-20664
Zoho ManageEngine ADSelfService Plus 5.x before build 5701 has XXE via an uploaded product license.
Published 2019-01-03 · Modified
9.8EPSS 0.081
CVE-2019-18411
Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally. Attackers could use the reset password function and control the system to send the authentication code back to the channel that the attackers own.
Published 2019-11-06 · Modified
8.8EPSS 0.023
CVE-2019-12876
Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalation from low level privileges to System.
Published 2019-07-17 · Modified
8.5EPSS 0.046
CVE-2023-28342
Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.
Published 2023-04-05 · Modified
7.5EPSS 0.783
CVE-2019-7161
An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.x through build 5704. It uses fixed ciphering keys to protect information, giving the capacity for an attacker to decipher any protected data.
Published 2019-03-18 · Modified
7.5EPSS 0.056
CVE-2018-20484
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation.
Published 2018-12-26 · Modified
6.11 PoCEPSS 0.053
CVE-2018-20485
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature.
Published 2018-12-26 · Modified
6.11 PoCEPSS 0.053
CVE-2019-8346
In Zoho ManageEngine ADSelfService Plus 5.x through 5704, an authorization.do cross-site Scripting (XSS) vulnerability allows for an unauthenticated manipulation of the JavaScript code by injecting the HTTP form parameter adscsrf. An attacker can use this to capture a user's AD self-service password reset and MFA token.
Published 2019-05-24 · Modified
6.1EPSS 0.035
CVE-2019-11511
Zoho ManageEngine ADSelfService Plus before build 5708 has XSS via the mobile app API.
Published 2019-04-25 · Modified
6.1EPSS 0.021
CVE-2019-18781
An open redirect vulnerability was discovered in Zoho ManageEngine ADSelfService Plus 5.x before 5809 that allows attackers to force users who click on a crafted link to be sent to a specified external site.
Published 2019-12-18 · Modified
6.1EPSS 0.018