Product:

Manageengine_adselfservice_plus

(Zohocorp)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 48
Date Id Summary Products Score Patch Annotated
2019-07-17 CVE-2019-12876 Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalation from low level privileges to System. Manageengine_admanager_plus, Manageengine_adselfservice_plus, Manageengine_desktop_central 7.3
2019-06-17 CVE-2019-12476 An authentication bypass vulnerability in the password reset functionality in Zoho ManageEngine ADSelfService Plus before 5.0.6 allows an attacker with physical access to gain a shell with SYSTEM privileges via the restricted thick client browser. The attack uses a long sequence of crafted keyboard input. Manageengine_adselfservice_plus 6.8
2019-04-25 CVE-2019-11511 Zoho ManageEngine ADSelfService Plus before build 5708 has XSS via the mobile app API. Manageengine_adselfservice_plus 6.1
2019-05-24 CVE-2019-8346 In Zoho ManageEngine ADSelfService Plus 5.x through 5704, an authorization.do cross-site Scripting (XSS) vulnerability allows for an unauthenticated manipulation of the JavaScript code by injecting the HTTP form parameter adscsrf. An attacker can use this to capture a user's AD self-service password reset and MFA token. Manageengine_adselfservice_plus 6.1
2019-01-03 CVE-2018-20664 Zoho ManageEngine ADSelfService Plus 5.x before build 5701 has XXE via an uploaded product license. Manageengine_adselfservice_plus 9.8
2018-12-26 CVE-2018-20485 Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature. Manageengine_adselfservice_plus 6.1
2018-12-26 CVE-2018-20484 Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation. Manageengine_adselfservice_plus 6.1
2015-01-07 CVE-2014-3779 Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine ADSelfService Plus before 5.2 Build 5202 allows remote attackers to inject arbitrary web script or HTML via the name parameter to GroupSubscription.do. Manageengine_adselfservice_plus N/A
2012-08-23 CVE-2011-5105 Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in ZOHO ManageEngine ADSelfService Plus 4.5 Build 4521 allow remote attackers to inject arbitrary web script or HTML via the (1) searchType and (2) searchString parameters, a different vulnerability than CVE-2010-3274. Manageengine_adselfservice_plus N/A
2011-02-17 CVE-2010-3274 Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in the Employee Search Engine in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 allow remote attackers to inject arbitrary web script or HTML via the searchString parameter in a (1) showList or (2) Search action. Manageengine_adselfservice_plus N/A