Vulnerability Description
A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The j_username parameter seems to be vulnerable and a reverse shell could be obtained if a privileged user exports "User Attempts Audit Report" as CSV file. Note: The vendor disputes this vulnerability, claiming "This is not a valid vulnerability in our ADSSP product. We don't see this as a security issue at our side.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zohocorp | Manageengine Adselfservice Plus | 6.1 |
Related Weaknesses (CWE)
References
- https://docs.unsafe-inline.com/0day/manageengine-adselfservice-plus-6.1-csv-injeExploitThird Party Advisory
- https://docs.unsafe-inline.com/0day/manageengine-adselfservice-plus-6.1-csv-injeExploitThird Party Advisory
FAQ
What is CVE-2021-33256?
CVE-2021-33256 is a vulnerability with a CVSS score of 8.8 (HIGH). A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The j_username parameter seems to be vulner...
How severe is CVE-2021-33256?
CVE-2021-33256 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-33256?
Check the references section above for vendor advisories and patch information. Affected products include: Zohocorp Manageengine Adselfservice Plus.