8.8

CVE-2017-17552

Exploit
/LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resulting in a bypass of CSRF protection, or potentially masquerading a malicious URL as trusted.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZohocorpManageengine Admanager Plus Version6.6 Update6601
ZohocorpManageengine Admanager Plus Version6.6 Update6602
ZohocorpManageengine Admanager Plus Version6.6 Update6610
ZohocorpManageengine Admanager Plus Version6.6 Update6611
ZohocorpManageengine Admanager Plus Version6.6 Update6612
ZohocorpManageengine Admanager Plus Version6.6 Update6613
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.33% 0.556
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.