CVE-2019-18411
published 2019-11-06CVE-2019-18411: Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be…
PriorityP344high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
2.33%
81.4th percentile
Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally. Attackers could use the reset password function and control the system to send the authentication code back to the channel that the attackers own.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zohocorp | manageengine_adselfservice_plus | — | — |
| zohocorp | manageengine_adselfservice_plus | — | — |
| zohocorp | manageengine_adselfservice_plus | — | — |
| zohocorp | manageengine_adselfservice_plus | — | — |
| zohocorp | manageengine_adselfservice_plus | — | — |
| zohocorp | manageengine_adselfservice_plus | — | — |
| zohocorp | manageengine_adselfservice_plus | — | — |
| zohocorp | manageengine_adselfservice_plus | — | — |
| zohocorp | manageengine_adselfservice_plus | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-11-06
Published