Manageengine Adselfservice Plus vulnerabilities

5 known vulnerabilities affecting manageengine/adselfservice_plus.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2025-3833HIGHCVSS 8.1fixed in 65142025-05-14
CVE-2025-3833 [HIGH] CWE-89 CVE-2025-3833: Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports.
cvelistv5nvd
CVE-2025-1723HIGHCVSS 8.1fixed in 65112025-03-03
CVE-2025-1723 [HIGH] CWE-287 CVE-2025-1723: Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have the potential to exploit this bug.
cvelistv5nvd
CVE-2024-27310MEDIUMCVSS 6.5fixed in 64012024-05-27
CVE-2024-27310 [MEDIUM] CWE-90 CVE-2024-27310: Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP input.
cvelistv5nvd
CVE-2024-0252HIGHCVSS 8.8fixed in 64022024-01-11
CVE-2024-0252 [HIGH] CWE-94 CVE-2024-0252: ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer component. Authentication is required in order to exploit this vulnerability.
cvelistv5nvd
CVE-2023-35719MEDIUMCVSS 6.8v6.1 Build 61222023-09-06
CVE-2023-35719 [MEDIUM] CWE-345 CVE-2023-35719: ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentic ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of ManageEngine ADSelfService Plus. Authentication is not required to exploit this vulnerability. The specific flaw
cvelistv5nvd