Vulnerabilities > Zohocorp > Manageengine Adselfservice Plus > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-11-15 CVE-2023-6105 Unspecified vulnerability in Zohocorp products
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed.
local
low complexity
zohocorp
5.5
2023-09-06 CVE-2023-35719 Insufficient Verification of Data Authenticity vulnerability in Zohocorp Manageengine Adselfservice Plus 6.1
ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability.
low complexity
zohocorp CWE-345
6.8
2022-07-04 CVE-2022-34829 Unspecified vulnerability in Zohocorp Manageengine Adselfservice Plus
Zoho ManageEngine ADSelfService Plus before 6203 allows a denial of service (application restart) via a crafted payload to the Mobile App Deployment API.
network
low complexity
zohocorp
5.0
2022-05-20 CVE-2022-28987 Unspecified vulnerability in Zohocorp Manageengine Adselfservice Plus 6.1
Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST request to /ServletAPI/accounts/login.
network
low complexity
zohocorp
5.0
2022-04-18 CVE-2022-28810 Use of Hard-coded Credentials vulnerability in Zohocorp Manageengine Adselfservice Plus
Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature.
network
low complexity
zohocorp CWE-798
6.8
2022-04-07 CVE-2022-24681 Cross-site Scripting vulnerability in Zohocorp Manageengine Adselfservice Plus
Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen.
network
low complexity
zohocorp CWE-79
6.1
2022-01-03 CVE-2021-20147 Information Exposure Through Discrepancy vulnerability in Zohocorp Manageengine Adselfservice Plus
ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI.
network
low complexity
zohocorp CWE-203
5.0
2022-01-03 CVE-2021-20148 Files or Directories Accessible to External Parties vulnerability in Zohocorp Manageengine Adselfservice Plus
ManageEngine ADSelfService Plus below build 6116 stores the password policy file for each domain under the html/ web root with a predictable filename based on the domain name.
network
low complexity
zohocorp CWE-552
4.3
2021-08-30 CVE-2021-37416 Cross-site Scripting vulnerability in Zohocorp Manageengine Adselfservice Plus
Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page.
network
zohocorp CWE-79
4.3
2021-08-30 CVE-2021-37417 Improper Authentication vulnerability in Zohocorp Manageengine Adselfservice Plus
Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation.
network
low complexity
zohocorp CWE-287
5.0