SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-24681

Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen.

MEDIUM 6.1EPSS 3.62%

Does this matter?

Lower severity and a low EPSS score (3.62%). Track it; it rarely justifies an emergency change on its own.

Description

Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
3.62% probability · 89th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
zohocorp/manageengine adselfservice plus
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.