Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Manageengine_adselfservice_plus
(Zohocorp)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 48 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2019-07-17 | CVE-2019-12876 | Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalation from low level privileges to System. | Manageengine_admanager_plus, Manageengine_adselfservice_plus, Manageengine_desktop_central | 7.3 | ||
2019-06-17 | CVE-2019-12476 | An authentication bypass vulnerability in the password reset functionality in Zoho ManageEngine ADSelfService Plus before 5.0.6 allows an attacker with physical access to gain a shell with SYSTEM privileges via the restricted thick client browser. The attack uses a long sequence of crafted keyboard input. | Manageengine_adselfservice_plus | 6.8 | ||
2019-04-25 | CVE-2019-11511 | Zoho ManageEngine ADSelfService Plus before build 5708 has XSS via the mobile app API. | Manageengine_adselfservice_plus | 6.1 | ||
2019-05-24 | CVE-2019-8346 | In Zoho ManageEngine ADSelfService Plus 5.x through 5704, an authorization.do cross-site Scripting (XSS) vulnerability allows for an unauthenticated manipulation of the JavaScript code by injecting the HTTP form parameter adscsrf. An attacker can use this to capture a user's AD self-service password reset and MFA token. | Manageengine_adselfservice_plus | 6.1 | ||
2019-01-03 | CVE-2018-20664 | Zoho ManageEngine ADSelfService Plus 5.x before build 5701 has XXE via an uploaded product license. | Manageengine_adselfservice_plus | 9.8 | ||
2018-12-26 | CVE-2018-20485 | Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature. | Manageengine_adselfservice_plus | 6.1 | ||
2018-12-26 | CVE-2018-20484 | Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation. | Manageengine_adselfservice_plus | 6.1 | ||
2015-01-07 | CVE-2014-3779 | Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine ADSelfService Plus before 5.2 Build 5202 allows remote attackers to inject arbitrary web script or HTML via the name parameter to GroupSubscription.do. | Manageengine_adselfservice_plus | N/A | ||
2012-08-23 | CVE-2011-5105 | Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in ZOHO ManageEngine ADSelfService Plus 4.5 Build 4521 allow remote attackers to inject arbitrary web script or HTML via the (1) searchType and (2) searchString parameters, a different vulnerability than CVE-2010-3274. | Manageengine_adselfservice_plus | N/A | ||
2011-02-17 | CVE-2010-3274 | Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in the Employee Search Engine in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 allow remote attackers to inject arbitrary web script or HTML via the searchString parameter in a (1) showList or (2) Search action. | Manageengine_adselfservice_plus | N/A |