6.1

CVE-2022-24681

Exploit

Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen.

Data is provided by the National Vulnerability Database (NVD)
ZohocorpManageengine Adselfservice Plus Version6.1 Update-
ZohocorpManageengine Adselfservice Plus Version6.1 Update6100
ZohocorpManageengine Adselfservice Plus Version6.1 Update6101
ZohocorpManageengine Adselfservice Plus Version6.1 Update6102
ZohocorpManageengine Adselfservice Plus Version6.1 Update6103
ZohocorpManageengine Adselfservice Plus Version6.1 Update6104
ZohocorpManageengine Adselfservice Plus Version6.1 Update6105
ZohocorpManageengine Adselfservice Plus Version6.1 Update6106
ZohocorpManageengine Adselfservice Plus Version6.1 Update6107
ZohocorpManageengine Adselfservice Plus Version6.1 Update6108
ZohocorpManageengine Adselfservice Plus Version6.1 Update6109
ZohocorpManageengine Adselfservice Plus Version6.1 Update6110
ZohocorpManageengine Adselfservice Plus Version6.1 Update6111
ZohocorpManageengine Adselfservice Plus Version6.1 Update6112
ZohocorpManageengine Adselfservice Plus Version6.1 Update6113
ZohocorpManageengine Adselfservice Plus Version6.1 Update6114
ZohocorpManageengine Adselfservice Plus Version6.1 Update6115
ZohocorpManageengine Adselfservice Plus Version6.1 Update6116
ZohocorpManageengine Adselfservice Plus Version6.1 Update6117
ZohocorpManageengine Adselfservice Plus Version6.1 Update6118
ZohocorpManageengine Adselfservice Plus Version6.1 Update6119
ZohocorpManageengine Adselfservice Plus Version6.1 Update6120
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 21.61% 0.955
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.