Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2018-20485 โ€” Cross-site Scripting in Manageengine Adselfservice Plus

Severity
6.1MEDIUMNVD
EPSS
1.7%
top 17.67%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedDec 26
Latest updateMay 14

Description

Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

๐Ÿ”ดVulnerability Details

2
GHSA
GHSA-8fr8-8gvq-h5f8: Zoho ManageEngine ADSelfService Plus 5โ†—2022-05-14
โ–ถ
CVEList
CVE-2018-20485: Zoho ManageEngine ADSelfService Plus 5โ†—2018-12-26
โ–ถ

๐Ÿ’ฅExploits & PoCs

1
Exploit-DB
Zoho ManageEngine ADSelfService Plus 5.7 < 5702 build - Cross-Site Scriptingโ†—2019-05-09
โ–ถ
CVE-2018-20485 โ€” Cross-site Scripting | cvebase