CVE-2019-18411

Severity
8.8HIGH
EPSS
0.2%
top 61.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 6
Latest updateMay 24

Description

Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally. Attackers could use the reset password function and control the system to send the authentication code back to the channel that the attackers own.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-538j-xxfp-r55q: Zoho ManageEngine ADSelfService Plus 52022-05-24
CVEList
CVE-2019-18411: Zoho ManageEngine ADSelfService Plus 52019-11-06
CVE-2019-18411 (HIGH CVSS 8.8) | Zoho ManageEngine ADSelfService Plu | cvebase.io