6.1

CVE-2019-18781

An open redirect vulnerability was discovered in Zoho ManageEngine ADSelfService Plus 5.x before 5809 that allows attackers to force users who click on a crafted link to be sent to a specified external site.

Data is provided by the National Vulnerability Database (NVD)
ZohocorpManageengine Adselfservice Plus Version5.0 Update5000
ZohocorpManageengine Adselfservice Plus Version5.0 Update5001
ZohocorpManageengine Adselfservice Plus Version5.0 Update5002
ZohocorpManageengine Adselfservice Plus Version5.0 Update5010
ZohocorpManageengine Adselfservice Plus Version5.0 Update5011
ZohocorpManageengine Adselfservice Plus Version5.0 Update5020
ZohocorpManageengine Adselfservice Plus Version5.0 Update5021
ZohocorpManageengine Adselfservice Plus Version5.0 Update5022
ZohocorpManageengine Adselfservice Plus Version5.0 Update5030
ZohocorpManageengine Adselfservice Plus Version5.0 Update5032
ZohocorpManageengine Adselfservice Plus Version5.0 Update5040
ZohocorpManageengine Adselfservice Plus Version5.0 Update5041
ZohocorpManageengine Adselfservice Plus Version5.1 Update5100
ZohocorpManageengine Adselfservice Plus Version5.1 Update5101
ZohocorpManageengine Adselfservice Plus Version5.1 Update5102
ZohocorpManageengine Adselfservice Plus Version5.1 Update5103
ZohocorpManageengine Adselfservice Plus Version5.1 Update5104
ZohocorpManageengine Adselfservice Plus Version5.1 Update5105
ZohocorpManageengine Adselfservice Plus Version5.1 Update5106
ZohocorpManageengine Adselfservice Plus Version5.1 Update5107
ZohocorpManageengine Adselfservice Plus Version5.1 Update5108
ZohocorpManageengine Adselfservice Plus Version5.1 Update5109
ZohocorpManageengine Adselfservice Plus Version5.1 Update5110
ZohocorpManageengine Adselfservice Plus Version5.1 Update5111
ZohocorpManageengine Adselfservice Plus Version5.1 Update5112
ZohocorpManageengine Adselfservice Plus Version5.1 Update5113
ZohocorpManageengine Adselfservice Plus Version5.1 Update5114
ZohocorpManageengine Adselfservice Plus Version5.1 Update5115
ZohocorpManageengine Adselfservice Plus Version5.1 Update5116
ZohocorpManageengine Adselfservice Plus Version5.2 Update5200
ZohocorpManageengine Adselfservice Plus Version5.2 Update5201
ZohocorpManageengine Adselfservice Plus Version5.2 Update5202
ZohocorpManageengine Adselfservice Plus Version5.2 Update5203
ZohocorpManageengine Adselfservice Plus Version5.2 Update5204
ZohocorpManageengine Adselfservice Plus Version5.2 Update5205
ZohocorpManageengine Adselfservice Plus Version5.2 Update5206
ZohocorpManageengine Adselfservice Plus Version5.2 Update5207
ZohocorpManageengine Adselfservice Plus Version5.3 Update5300
ZohocorpManageengine Adselfservice Plus Version5.3 Update5301
ZohocorpManageengine Adselfservice Plus Version5.3 Update5302
ZohocorpManageengine Adselfservice Plus Version5.3 Update5303
ZohocorpManageengine Adselfservice Plus Version5.3 Update5304
ZohocorpManageengine Adselfservice Plus Version5.3 Update5305
ZohocorpManageengine Adselfservice Plus Version5.3 Update5306
ZohocorpManageengine Adselfservice Plus Version5.3 Update5307
ZohocorpManageengine Adselfservice Plus Version5.3 Update5308
ZohocorpManageengine Adselfservice Plus Version5.3 Update5309
ZohocorpManageengine Adselfservice Plus Version5.3 Update5310
ZohocorpManageengine Adselfservice Plus Version5.3 Update5311
ZohocorpManageengine Adselfservice Plus Version5.3 Update5312
ZohocorpManageengine Adselfservice Plus Version5.3 Update5313
ZohocorpManageengine Adselfservice Plus Version5.3 Update5314
ZohocorpManageengine Adselfservice Plus Version5.3 Update5315
ZohocorpManageengine Adselfservice Plus Version5.3 Update5316
ZohocorpManageengine Adselfservice Plus Version5.3 Update5317
ZohocorpManageengine Adselfservice Plus Version5.3 Update5318
ZohocorpManageengine Adselfservice Plus Version5.3 Update5319
ZohocorpManageengine Adselfservice Plus Version5.3 Update5320
ZohocorpManageengine Adselfservice Plus Version5.3 Update5321
ZohocorpManageengine Adselfservice Plus Version5.3 Update5322
ZohocorpManageengine Adselfservice Plus Version5.3 Update5323
ZohocorpManageengine Adselfservice Plus Version5.3 Update5324
ZohocorpManageengine Adselfservice Plus Version5.3 Update5325
ZohocorpManageengine Adselfservice Plus Version5.3 Update5326
ZohocorpManageengine Adselfservice Plus Version5.3 Update5327
ZohocorpManageengine Adselfservice Plus Version5.3 Update5328
ZohocorpManageengine Adselfservice Plus Version5.3 Update5329
ZohocorpManageengine Adselfservice Plus Version5.3 Update5330
ZohocorpManageengine Adselfservice Plus Version5.4 Update5400
ZohocorpManageengine Adselfservice Plus Version5.5 Update5500
ZohocorpManageengine Adselfservice Plus Version5.5 Update5501
ZohocorpManageengine Adselfservice Plus Version5.5 Update5502
ZohocorpManageengine Adselfservice Plus Version5.5 Update5503
ZohocorpManageengine Adselfservice Plus Version5.5 Update5504
ZohocorpManageengine Adselfservice Plus Version5.5 Update5505
ZohocorpManageengine Adselfservice Plus Version5.5 Update5506
ZohocorpManageengine Adselfservice Plus Version5.5 Update5507
ZohocorpManageengine Adselfservice Plus Version5.5 Update5508
ZohocorpManageengine Adselfservice Plus Version5.5 Update5509
ZohocorpManageengine Adselfservice Plus Version5.5 Update5510
ZohocorpManageengine Adselfservice Plus Version5.5 Update5511
ZohocorpManageengine Adselfservice Plus Version5.5 Update5512
ZohocorpManageengine Adselfservice Plus Version5.5 Update5513
ZohocorpManageengine Adselfservice Plus Version5.5 Update5514
ZohocorpManageengine Adselfservice Plus Version5.5 Update5515
ZohocorpManageengine Adselfservice Plus Version5.5 Update5516
ZohocorpManageengine Adselfservice Plus Version5.5 Update5517
ZohocorpManageengine Adselfservice Plus Version5.5 Update5518
ZohocorpManageengine Adselfservice Plus Version5.5 Update5519
ZohocorpManageengine Adselfservice Plus Version5.5 Update5520
ZohocorpManageengine Adselfservice Plus Version5.5 Update5521
ZohocorpManageengine Adselfservice Plus Version5.6 Update5600
ZohocorpManageengine Adselfservice Plus Version5.6 Update5601
ZohocorpManageengine Adselfservice Plus Version5.6 Update5602
ZohocorpManageengine Adselfservice Plus Version5.6 Update5603
ZohocorpManageengine Adselfservice Plus Version5.6 Update5604
ZohocorpManageengine Adselfservice Plus Version5.6 Update5605
ZohocorpManageengine Adselfservice Plus Version5.6 Update5606
ZohocorpManageengine Adselfservice Plus Version5.6 Update5607
ZohocorpManageengine Adselfservice Plus Version5.7 Update5700
ZohocorpManageengine Adselfservice Plus Version5.7 Update5701
ZohocorpManageengine Adselfservice Plus Version5.7 Update5702
ZohocorpManageengine Adselfservice Plus Version5.7 Update5703
ZohocorpManageengine Adselfservice Plus Version5.7 Update5704
ZohocorpManageengine Adselfservice Plus Version5.7 Update5705
ZohocorpManageengine Adselfservice Plus Version5.7 Update5706
ZohocorpManageengine Adselfservice Plus Version5.7 Update5707
ZohocorpManageengine Adselfservice Plus Version5.7 Update5708
ZohocorpManageengine Adselfservice Plus Version5.7 Update5709
ZohocorpManageengine Adselfservice Plus Version5.7 Update5710
ZohocorpManageengine Adselfservice Plus Version5.8 Update5800
ZohocorpManageengine Adselfservice Plus Version5.8 Update5801
ZohocorpManageengine Adselfservice Plus Version5.8 Update5802
ZohocorpManageengine Adselfservice Plus Version5.8 Update5803
ZohocorpManageengine Adselfservice Plus Version5.8 Update5804
ZohocorpManageengine Adselfservice Plus Version5.8 Update5805
ZohocorpManageengine Adselfservice Plus Version5.8 Update5806
ZohocorpManageengine Adselfservice Plus Version5.8 Update5807
ZohocorpManageengine Adselfservice Plus Version5.8 Update5808
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.41% 0.602
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.