cbcvebase.
CVE-2019-18411
published 2019-11-06

CVE-2019-18411: Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be…

PriorityP344high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
2.33%
81.4th percentile
Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally. Attackers could use the reset password function and control the system to send the authentication code back to the channel that the attackers own.

Affected

9 ranges
VendorProductVersion rangeFixed in
zohocorpmanageengine_adselfservice_plus
zohocorpmanageengine_adselfservice_plus
zohocorpmanageengine_adselfservice_plus
zohocorpmanageengine_adselfservice_plus
zohocorpmanageengine_adselfservice_plus
zohocorpmanageengine_adselfservice_plus
zohocorpmanageengine_adselfservice_plus
zohocorpmanageengine_adselfservice_plus
zohocorpmanageengine_adselfservice_plus

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.