6.1
CVSSv3

CVE-2019-8346

Published: 24/05/2019 Updated: 29/05/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

In Zoho ManageEngine ADSelfService Plus 5.x through 5704, an authorization.do cross-site Scripting (XSS) vulnerability allows for an unauthenticated manipulation of the JavaScript code by injecting the HTTP form parameter adscsrf. An attacker can use this to capture a user's AD self-service password reset and MFA token.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zohocorp manageengine adselfservice plus 5.0

zohocorp manageengine adselfservice plus 5.1

zohocorp manageengine adselfservice plus 5.2

zohocorp manageengine adselfservice plus 5.3

zohocorp manageengine adselfservice plus 5.4

zohocorp manageengine adselfservice plus 5.5

zohocorp manageengine adselfservice plus 5.7

zohocorp manageengine adselfservice plus 5.6