VulnerabilityModified
CVE-2019-18781
An open redirect vulnerability was discovered in Zoho ManageEngine ADSelfService Plus 5.x before 5809 that allows attackers to force users who click on a crafted link to be sent to a specified external site.
MEDIUM 6.1EPSS 1.84%
Does this matter?
Lower severity and a low EPSS score (1.84%). Track it; it rarely justifies an emergency change on its own.
Description
An open redirect vulnerability was discovered in Zoho ManageEngine ADSelfService Plus 5.x before 5809 that allows attackers to force users who click on a crafted link to be sent to a specified external site.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.84% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- zohocorp/manageengine adselfservice plus
- Source
- cve@mitre.org
References
- https://pitstop.manageengine.com/portal/community/topic/adselfservice-plus-5809-releaseVendor Advisory
- https://www.manageengine.com/products/self-service-password/release-notes.htmlRelease Notes, Vendor Advisory
- https://pitstop.manageengine.com/portal/community/topic/adselfservice-plus-5809-releaseVendor Advisory
- https://www.manageengine.com/products/self-service-password/release-notes.htmlRelease Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.