Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2018-20484 — Cross-site Scripting in Manageengine Adselfservice Plus

Severity
6.1MEDIUMNVD
EPSS
1.7%
top 17.67%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedDec 26
Latest updateMay 14

Description

Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-4542-x8v2-hf3g: Zoho ManageEngine ADSelfService Plus 5↗2022-05-14
â–¶
CVEList
CVE-2018-20484: Zoho ManageEngine ADSelfService Plus 5↗2018-12-26
â–¶

💥Exploits & PoCs

1
Exploit-DB
Zoho ManageEngine ADSelfService Plus 5.7 < 5702 build - Cross-Site Scripting↗2019-05-09
â–¶
CVE-2018-20484 — Cross-site Scripting | cvebase