VYPR

Manageengine Adselfservice Plus

by Zohocorp

CVEs (52)

  • CVE-2024-0252HigJan 11, 2024
    risk 0.58cvss 8.8epss 0.08

    ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer component. Authentication is required in order to exploit this vulnerability.

  • CVE-2019-18411HigNov 6, 2019
    risk 0.57cvss 8.8epss 0.02

    Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally. Attackers could use the…

  • CVE-2026-1367HigFeb 23, 2026
    risk 0.55cvss 8.3epss 0.07

    Zohocorp ManageEngine ADSelfService Plus versions 6522 and below are vulnerable to authenticated SQL Injection in the search report option.

  • CVE-2025-3833HigMay 14, 2025
    risk 0.55cvss 8.1epss 0.38

    Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports.

  • CVE-2023-28342HigApr 5, 2023
    risk 0.55cvss 7.5epss 0.78

    Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.

  • CVE-2025-1723HigMar 3, 2025
    risk 0.53cvss 8.1epss 0.01

    Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have the potential to exploit this bug.

  • CVE-2022-34829HigJul 4, 2022
    risk 0.49cvss 7.5epss 0.04

    Zoho ManageEngine ADSelfService Plus before 6203 allows a denial of service (application restart) via a crafted payload to the Mobile App Deployment API.

  • CVE-2019-7161HigMar 21, 2019
    risk 0.49cvss 7.5epss 0.06

    An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.x through build 5704. It uses fixed ciphering keys to protect information, giving the capacity for an attacker to decipher any protected data.

  • CVE-2019-12876HigJul 17, 2019
    risk 0.48cvss 7.3epss 0.05

    Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalation from low level privileges to System.

  • CVE-2023-35719MedSep 6, 2023
    risk 0.46cvss 6.8epss 0.26

    ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of ManageEngine ADSelfService Plus.…

  • CVE-2019-12476MedJun 17, 2019
    risk 0.44cvss 6.8epss 0.02

    An authentication bypass vulnerability in the password reset functionality in Zoho ManageEngine ADSelfService Plus before 5.0.6 allows an attacker with physical access to gain a shell with SYSTEM privileges via the restricted thick client browser. The attack uses a long sequence…

  • CVE-2018-20485MedDec 26, 2018
    risk 0.43cvss 6.1epss 0.05

    Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature.

  • CVE-2018-20484MedDec 26, 2018
    risk 0.43cvss 6.1epss 0.05

    Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation.

  • CVE-2022-24681MedApr 7, 2022
    risk 0.40cvss 6.1epss 0.04

    Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen.

  • CVE-2021-37416MedAug 30, 2021
    risk 0.40cvss 6.1epss 0.03

    Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page.

  • CVE-2021-27956MedMay 20, 2021
    risk 0.40cvss 6.1epss 0.02

    Zoho ManageEngine ADSelfService Plus before 6104 allows stored XSS on the /webclient/index.html#/directory-search user search page via the e-mail address field.

  • CVE-2021-27214MedFeb 19, 2021
    risk 0.40cvss 6.1epss 0.02

    A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote unauthenticated attacker to perform blind HTTP requests or perform a Cross-site scripting (XSS) attack against the administrative…

  • CVE-2019-18781MedDec 18, 2019
    risk 0.40cvss 6.1epss 0.02

    An open redirect vulnerability was discovered in Zoho ManageEngine ADSelfService Plus 5.x before 5809 that allows attackers to force users who click on a crafted link to be sent to a specified external site.

  • CVE-2019-8346MedMay 24, 2019
    risk 0.40cvss 6.1epss 0.04

    In Zoho ManageEngine ADSelfService Plus 5.x through 5704, an authorization.do cross-site Scripting (XSS) vulnerability allows for an unauthenticated manipulation of the JavaScript code by injecting the HTTP form parameter adscsrf. An attacker can use this to capture a user's AD…

  • CVE-2019-11511MedApr 25, 2019
    risk 0.40cvss 6.1epss 0.02

    Zoho ManageEngine ADSelfService Plus before build 5708 has XSS via the mobile app API.