CVE-2022-28810
- EPSS 70.97%
- Veröffentlicht 18.04.2022 13:15:08
- Zuletzt bearbeitet 31.10.2025 14:40:07
Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attacker...
CVE-2022-24681
- EPSS 3.62%
- Veröffentlicht 07.04.2022 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:50:51
Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen.
CVE-2021-20148
- EPSS 1.12%
- Veröffentlicht 03.01.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 05:46:00
ManageEngine ADSelfService Plus below build 6116 stores the password policy file for each domain under the html/ web root with a predictable filename based on the domain name. When ADSSP is configured with multiple Windows domains, a user from one do...
CVE-2021-20147
- EPSS 6.9%
- Veröffentlicht 03.01.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 05:46:00
ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote attacker to determine whether a Windows domain user exists.
CVE-2021-37422
- EPSS 3.43%
- Veröffentlicht 10.09.2021 16:15:07
- Zuletzt bearbeitet 21.11.2024 06:15:07
Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases.
CVE-2021-37423
- EPSS 2.83%
- Veröffentlicht 10.09.2021 15:15:12
- Zuletzt bearbeitet 21.11.2024 06:15:08
Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to linked applications takeover.
CVE-2021-40539
- EPSS 98.96%
- Veröffentlicht 07.09.2021 17:15:07
- Zuletzt bearbeitet 05.11.2025 19:13:20
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.
CVE-2021-37417
- EPSS 4.75%
- Veröffentlicht 30.08.2021 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:15:07
Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation.
CVE-2021-37421
- EPSS 2.49%
- Veröffentlicht 30.08.2021 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:15:07
Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass.
CVE-2021-37416
- EPSS 2.93%
- Veröffentlicht 30.08.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:15:07
Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page.