Severity
9.8CRITICAL
EPSS
18.6%
top 4.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 30
Latest updateMay 24

Description

Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

๐Ÿ”ดVulnerability Details

2
GHSA
GHSA-93vf-46j6-q3jh: Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validationโ†—2022-05-24
โ–ถ
CVEList
CVE-2021-37417: Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validationโ†—2021-08-30
โ–ถ
CVE-2021-37417 (CRITICAL CVSS 9.8) | Zoho ManageEngine ADSelfService Plu | cvebase.io