VYPR

ADSelfService Plus

by Manageengine

CVEs (19)

  • CVE-2021-40539CriKEVSep 7, 2021
    risk 0.93cvss 9.8epss 0.99

    Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.

  • CVE-2021-28958CriJun 25, 2021
    risk 0.70cvss 9.8epss 0.73

    Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.

  • CVE-2019-3905CriJan 3, 2019
    risk 0.65cvss 10.0epss 0.03

    Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF.

  • CVE-2021-37424CriSep 21, 2021
    risk 0.64cvss 9.8epss 0.05

    ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover.

  • CVE-2021-33256HigAug 9, 2021
    risk 0.64cvss 8.8epss 0.79

    A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The j_username parameter seems to be vulnerable and a reverse shell could be obtained if a privileged user exports "User…

  • CVE-2020-11552CriAug 11, 2020
    risk 0.64cvss 9.8epss 0.07

    An elevation of privilege vulnerability exists in ManageEngine ADSelfService Plus before build 6003 because it does not properly enforce user privileges associated with a Certificate dialog. This vulnerability could allow an unauthenticated attacker to escalate privileges on a…

  • CVE-2024-0252HigJan 11, 2024
    risk 0.58cvss 8.8epss 0.08

    ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer component. Authentication is required in order to exploit this vulnerability.

  • CVE-2025-3833HigMay 14, 2025
    risk 0.55cvss 8.1epss 0.28

    Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports.

  • CVE-2025-1723HigMar 3, 2025
    risk 0.53cvss 8.1epss 0.01

    Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have the potential to exploit this bug.

  • CVE-2021-37419HigSep 21, 2021
    risk 0.49cvss 7.5epss 0.02

    Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to SSRF.

  • CVE-2019-7161HigMar 21, 2019
    risk 0.49cvss 7.5epss 0.06

    An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.x through build 5704. It uses fixed ciphering keys to protect information, giving the capacity for an attacker to decipher any protected data.

  • CVE-2023-35719MedSep 6, 2023
    risk 0.46cvss 6.8epss 0.26

    ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of ManageEngine ADSelfService Plus.…

  • CVE-2022-24681MedApr 7, 2022
    risk 0.40cvss 6.1epss 0.04

    Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen.

  • CVE-2021-27214MedFeb 19, 2021
    risk 0.40cvss 6.1epss 0.02

    A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote unauthenticated attacker to perform blind HTTP requests or perform a Cross-site scripting (XSS) attack against the administrative…

  • CVE-2021-31874MedJul 2, 2021
    risk 0.39cvss 5.9epss 0.04

    Zoho ManageEngine ADSelfService Plus before 6104, in rare situations, allows attackers to obtain sensitive information about the password-sync database application.

  • CVE-2024-27310MedMay 27, 2024
    risk 0.35cvss 5.3epss 0.02

    Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP input.

  • CVE-2021-20147MedJan 3, 2022
    risk 0.35cvss 5.3epss 0.07

    ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote attacker to determine whether a Windows domain user exists.

  • CVE-2021-20148MedJan 3, 2022
    risk 0.28cvss 4.3epss 0.01

    ManageEngine ADSelfService Plus below build 6116 stores the password policy file for each domain under the html/ web root with a predictable filename based on the domain name. When ADSSP is configured with multiple Windows domains, a user from one domain can obtain the password…

  • CVE-2026-11374Jun 23, 2026
    risk 0.00cvss epss 0.01

    In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.