CVE-2019-18411
Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.33%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally. Attackers could use the reset password function and control the system to send the authentication code back to the channel that the attackers own.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 2.33% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- zohocorp/manageengine adselfservice plus
- Source
- cve@mitre.org
References
- https://gist.github.com/aliceicl/e32fb4a17277c7db9e0256185ac03daeThird Party Advisory
- https://gist.github.com/aliceicl/e32fb4a17277c7db9e0256185ac03daeThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.