Manageengine Adselfservice Plus
by Zohocorp
CVEs (52)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-0252 | Hig | 0.58 | 8.8 | 0.08 | Jan 11, 2024 | ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer component. Authentication is required in order to exploit this vulnerability. | ||
| CVE-2019-18411 | Hig | 0.57 | 8.8 | 0.02 | Nov 6, 2019 | Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally. Attackers could use the… | ||
| CVE-2026-1367 | Hig | 0.55 | 8.3 | 0.07 | Feb 23, 2026 | Zohocorp ManageEngine ADSelfService Plus versions 6522 and below are vulnerable to authenticated SQL Injection in the search report option. | ||
| CVE-2025-3833 | Hig | 0.55 | 8.1 | 0.38 | May 14, 2025 | Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports. | ||
| CVE-2023-28342 | Hig | 0.55 | 7.5 | 0.78 | Apr 5, 2023 | Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API. | ||
| CVE-2025-1723 | Hig | 0.53 | 8.1 | 0.01 | Mar 3, 2025 | Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have the potential to exploit this bug. | ||
| CVE-2022-34829 | Hig | 0.49 | 7.5 | 0.04 | Jul 4, 2022 | Zoho ManageEngine ADSelfService Plus before 6203 allows a denial of service (application restart) via a crafted payload to the Mobile App Deployment API. | ||
| CVE-2019-7161 | Hig | 0.49 | 7.5 | 0.06 | Mar 21, 2019 | An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.x through build 5704. It uses fixed ciphering keys to protect information, giving the capacity for an attacker to decipher any protected data. | ||
| CVE-2019-12876 | Hig | 0.48 | 7.3 | 0.05 | Jul 17, 2019 | Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalation from low level privileges to System. | ||
| CVE-2023-35719 | Med | 0.46 | 6.8 | 0.26 | Sep 6, 2023 | ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of ManageEngine ADSelfService Plus.… | ||
| CVE-2019-12476 | Med | 0.44 | 6.8 | 0.02 | Jun 17, 2019 | An authentication bypass vulnerability in the password reset functionality in Zoho ManageEngine ADSelfService Plus before 5.0.6 allows an attacker with physical access to gain a shell with SYSTEM privileges via the restricted thick client browser. The attack uses a long sequence… | ||
| CVE-2018-20485 | Med | 0.43 | 6.1 | 0.05 | Dec 26, 2018 | Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature. | ||
| CVE-2018-20484 | Med | 0.43 | 6.1 | 0.05 | Dec 26, 2018 | Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation. | ||
| CVE-2022-24681 | Med | 0.40 | 6.1 | 0.04 | Apr 7, 2022 | Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen. | ||
| CVE-2021-37416 | Med | 0.40 | 6.1 | 0.03 | Aug 30, 2021 | Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page. | ||
| CVE-2021-27956 | Med | 0.40 | 6.1 | 0.02 | May 20, 2021 | Zoho ManageEngine ADSelfService Plus before 6104 allows stored XSS on the /webclient/index.html#/directory-search user search page via the e-mail address field. | ||
| CVE-2021-27214 | Med | 0.40 | 6.1 | 0.02 | Feb 19, 2021 | A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote unauthenticated attacker to perform blind HTTP requests or perform a Cross-site scripting (XSS) attack against the administrative… | ||
| CVE-2019-18781 | Med | 0.40 | 6.1 | 0.02 | Dec 18, 2019 | An open redirect vulnerability was discovered in Zoho ManageEngine ADSelfService Plus 5.x before 5809 that allows attackers to force users who click on a crafted link to be sent to a specified external site. | ||
| CVE-2019-8346 | Med | 0.40 | 6.1 | 0.04 | May 24, 2019 | In Zoho ManageEngine ADSelfService Plus 5.x through 5704, an authorization.do cross-site Scripting (XSS) vulnerability allows for an unauthenticated manipulation of the JavaScript code by injecting the HTTP form parameter adscsrf. An attacker can use this to capture a user's AD… | ||
| CVE-2019-11511 | Med | 0.40 | 6.1 | 0.02 | Apr 25, 2019 | Zoho ManageEngine ADSelfService Plus before build 5708 has XSS via the mobile app API. |
- risk 0.58cvss 8.8epss 0.08
ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer component. Authentication is required in order to exploit this vulnerability.
- risk 0.57cvss 8.8epss 0.02
Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally. Attackers could use the…
- risk 0.55cvss 8.3epss 0.07
Zohocorp ManageEngine ADSelfService Plus versions 6522 and below are vulnerable to authenticated SQL Injection in the search report option.
- risk 0.55cvss 8.1epss 0.38
Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports.
- risk 0.55cvss 7.5epss 0.78
Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.
- risk 0.53cvss 8.1epss 0.01
Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have the potential to exploit this bug.
- risk 0.49cvss 7.5epss 0.04
Zoho ManageEngine ADSelfService Plus before 6203 allows a denial of service (application restart) via a crafted payload to the Mobile App Deployment API.
- risk 0.49cvss 7.5epss 0.06
An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.x through build 5704. It uses fixed ciphering keys to protect information, giving the capacity for an attacker to decipher any protected data.
- risk 0.48cvss 7.3epss 0.05
Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalation from low level privileges to System.
- risk 0.46cvss 6.8epss 0.26
ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of ManageEngine ADSelfService Plus.…
- risk 0.44cvss 6.8epss 0.02
An authentication bypass vulnerability in the password reset functionality in Zoho ManageEngine ADSelfService Plus before 5.0.6 allows an attacker with physical access to gain a shell with SYSTEM privileges via the restricted thick client browser. The attack uses a long sequence…
- risk 0.43cvss 6.1epss 0.05
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature.
- risk 0.43cvss 6.1epss 0.05
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation.
- risk 0.40cvss 6.1epss 0.04
Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen.
- risk 0.40cvss 6.1epss 0.03
Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page.
- risk 0.40cvss 6.1epss 0.02
Zoho ManageEngine ADSelfService Plus before 6104 allows stored XSS on the /webclient/index.html#/directory-search user search page via the e-mail address field.
- risk 0.40cvss 6.1epss 0.02
A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote unauthenticated attacker to perform blind HTTP requests or perform a Cross-site scripting (XSS) attack against the administrative…
- risk 0.40cvss 6.1epss 0.02
An open redirect vulnerability was discovered in Zoho ManageEngine ADSelfService Plus 5.x before 5809 that allows attackers to force users who click on a crafted link to be sent to a specified external site.
- risk 0.40cvss 6.1epss 0.04
In Zoho ManageEngine ADSelfService Plus 5.x through 5704, an authorization.do cross-site Scripting (XSS) vulnerability allows for an unauthenticated manipulation of the JavaScript code by injecting the HTTP form parameter adscsrf. An attacker can use this to capture a user's AD…
- risk 0.40cvss 6.1epss 0.02
Zoho ManageEngine ADSelfService Plus before build 5708 has XSS via the mobile app API.
Page 2 of 3