Vulnerability Description
/LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resulting in a bypass of CSRF protection, or potentially masquerading a malicious URL as trusted.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zohocorp | Manageengine Admanager Plus | < 6.6 |
Related Weaknesses (CWE)
References
- https://umbrielsecurity.wordpress.com/2018/01/31/dangerous-url-redirection-and-cExploitMitigationThird Party Advisory
- https://umbrielsecurity.wordpress.com/2018/01/31/dangerous-url-redirection-and-cExploitMitigationThird Party Advisory
FAQ
What is CVE-2017-17552?
CVE-2017-17552 is a vulnerability with a CVSS score of 8.8 (HIGH). /LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resulting in a bypass of CSRF protection, or potentially ma...
How severe is CVE-2017-17552?
CVE-2017-17552 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-17552?
Check the references section above for vendor advisories and patch information. Affected products include: Zohocorp Manageengine Admanager Plus.