Vulnerability Description
Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally. Attackers could use the reset password function and control the system to send the authentication code back to the channel that the attackers own.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zohocorp | Manageengine Adselfservice Plus | 5.0 |
Related Weaknesses (CWE)
References
- https://gist.github.com/aliceicl/e32fb4a17277c7db9e0256185ac03daeThird Party Advisory
- https://gist.github.com/aliceicl/e32fb4a17277c7db9e0256185ac03daeThird Party Advisory
FAQ
What is CVE-2019-18411?
CVE-2019-18411 is a vulnerability with a CVSS score of 8.8 (HIGH). Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled informatio...
How severe is CVE-2019-18411?
CVE-2019-18411 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-18411?
Check the references section above for vendor advisories and patch information. Affected products include: Zohocorp Manageengine Adselfservice Plus.