CVE-2021-37421
- EPSS 8.91%
- Veröffentlicht 30.08.2021 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:15:07
Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass.
CVE-2021-37417
- EPSS 18.58%
- Veröffentlicht 30.08.2021 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:15:07
Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation.
CVE-2021-37416
- EPSS 7%
- Veröffentlicht 30.08.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:15:07
Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page.
- EPSS 21.78%
- Veröffentlicht 30.08.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:08:11
Zoho ManageEngine ADSelfService Plus through 6102 allows unauthenticated remote code execution in non-English editions.
CVE-2021-33256
- EPSS 16.31%
- Veröffentlicht 09.08.2021 14:15:31
- Zuletzt bearbeitet 21.11.2024 06:08:34
A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The j_username parameter seems to be vulnerable and a reverse shell could be obtained if a pr...
CVE-2021-31874
- EPSS 1.22%
- Veröffentlicht 02.07.2021 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:06:24
Zoho ManageEngine ADSelfService Plus before 6104, in rare situations, allows attackers to obtain sensitive information about the password-sync database application.
CVE-2021-28958
- EPSS 40.01%
- Veröffentlicht 25.06.2021 12:15:08
- Zuletzt bearbeitet 21.11.2024 06:00:26
Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.
CVE-2021-27956
- EPSS 1.49%
- Veröffentlicht 20.05.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 05:58:54
Zoho ManageEngine ADSelfService Plus before 6104 allows stored XSS on the /webclient/index.html#/directory-search user search page via the e-mail address field.
CVE-2021-27214
- EPSS 10.52%
- Veröffentlicht 19.02.2021 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:57:36
A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote unauthenticated attacker to perform blind HTTP requests or perform a Cross-site scripting (XSS) attac...
CVE-2018-5353
- EPSS 15.29%
- Veröffentlicht 30.09.2020 18:15:15
- Zuletzt bearbeitet 21.11.2024 04:08:38
The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser window. An una...